leizongmin / js-xss

Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
http://jsxss.com
Other
5.2k stars 629 forks source link

src 引入时,报undefined #166

Closed sunft1996 closed 5 years ago

sunft1996 commented 5 years ago

这种方式引入时,浏览器警告CORB,MIME type 为 text/plain,无法引入 image

leizongmin commented 5 years ago

建议通过 https://unpkg.com/xss@1.0.6/dist/xss.min.js 来引入