Skip to content

Moved feDropShadow to the svg filter allowlist#795

Merged
cure53 merged 1 commit intocure53:mainfrom
SelfMadeSystem:patch-1
Apr 27, 2023
Merged

Moved feDropShadow to the svg filter allowlist#795
cure53 merged 1 commit intocure53:mainfrom
SelfMadeSystem:patch-1

Conversation

@SelfMadeSystem
Copy link
Copy Markdown
Contributor

@SelfMadeSystem SelfMadeSystem commented Apr 26, 2023

Summary

I moved the feDropShadow tag to the allowlist.

Background & Context

feDropShadow is used quite a bit. It was originally but there apparently because of an mXSS risk (#573 (comment)), but after asking about it, he has no knowledge of one (#573 (comment))

Tasks

  • Make sure there really isn't any mXSS

The reason it was there was because "If I remember correctly there was some mXSS risk connected to those", however I searched and couldn't find one (and neither could cure53 cure53#573 (comment)) and so I change it back.
@cure53 cure53 merged commit f3a5f0c into cure53:main Apr 27, 2023
@cure53
Copy link
Copy Markdown
Owner

cure53 commented Apr 27, 2023

LGTM, thanks! ✔️

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants