Skip to content

Handling of <a href="data:..."> #352

@evilpie

Description

@evilpie

We allow anchors in the default configuration and only restrict javascript: URLs. data: URLs (especially inside an iframe) might look like XSS: https://x.com/KwanAleister/status/1985542748930523233

Personally I don't think data: URLs are special here, you could also link to a HTTP page that shows an alert. I filed this issue mainly for tracking.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions