Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sanitizer.js: Add srcset in the allowed attributes #29968

Merged
merged 3 commits into from Jan 7, 2020

Conversation

XhmikosR
Copy link
Member

@XhmikosR XhmikosR commented Jan 7, 2020

Not sure if this should be backported

@XhmikosR XhmikosR added the js label Jan 7, 2020
@XhmikosR XhmikosR requested a review from Johann-S January 7, 2020 11:29
@Johann-S
Copy link
Member

Johann-S commented Jan 7, 2020

It's sanitized by Angular too here: https://github.com/angular/angular/blob/7.2.4/packages/core/src/sanitization/html_sanitizer.ts#L67

so it's a good change 👍

It depends if we plan to ship a new v4 release or not

@XhmikosR
Copy link
Member Author

XhmikosR commented Jan 7, 2020

I think I will try backporting this along with #29969. We do need to release a new 4.4.x version anyway.

@XhmikosR XhmikosR added this to Inbox in v5 via automation Jan 7, 2020
@XhmikosR XhmikosR added this to Inbox in v4.5.0 via automation Jan 7, 2020
@XhmikosR XhmikosR marked this pull request as ready for review January 7, 2020 20:12
@XhmikosR XhmikosR requested a review from a team as a code owner January 7, 2020 20:12
@XhmikosR XhmikosR merged commit 5638499 into master Jan 7, 2020
v5 automation moved this from Inbox to Shipped Jan 7, 2020
@XhmikosR XhmikosR deleted the master-xmr-sanitizer-srcset branch January 7, 2020 20:46
@XhmikosR XhmikosR moved this from Inbox to Cherry-picked in v4.5.0 Jan 23, 2020
@XhmikosR XhmikosR moved this from Cherry-picked to Shipped in v4.5.0 Feb 22, 2020
olsza pushed a commit to olsza/bootstrap that referenced this pull request Oct 3, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
v4.5.0
  
Shipped
v5
  
Shipped
Development

Successfully merging this pull request may close these issues.

None yet

2 participants