svnlabs / google-caja

Automatically exported from code.google.com/p/google-caja
0 stars 1 forks source link

Should whitelist tags that can appear in the ancestor chain of a container node. #1490

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
Putting anchors as children of anchor tags causes strange rearrangements of the 
content when innerHTML is changed.  Tables are similarly problematic.  We 
should whitelist those tags that behave sensibly and throw if the host page 
attempts to call attachDocument where it would be unsafe to do so.

Original issue reported on code.google.com by metaw...@gmail.com on 3 Jul 2012 at 9:39

GoogleCodeExporter commented 9 years ago

Original comment by kpreid@google.com on 11 Nov 2013 at 6:31