w3c / trusted-types

A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
https://w3c.github.io/trusted-types/dist/spec/
Other
606 stars 74 forks source link

https://html.spec.whatwg.org/#dom-range-createcontextualfragment should pass "'script'" #543

Closed mbrodesser-Igalia closed 1 week ago

mbrodesser-Igalia commented 2 months ago

To " Get Trusted Type compliant string".

Credits to @smaug---- for detecting this.