Closed zhuxindaba closed 2 years ago
From the docs:
"Security note: changing the parser settings can be risky. In particular, decodeEntities: false has known security concerns and a complete test suite does not exist for every possible combination of settings when used with sanitize-html. If security is your goal we recommend you use the defaults rather than changing parser, except for the lowerCaseTags option."
So there are bigger problems with using this option and that fact is already documented. This doesn't mean making progress on those issues through PRs would not be welcome, but right now it is not a recommended (or safe) practice. We would need to see a fix for the security concerns first though before it would make sense to tackle other issues with the setting.