You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Most projects should have a strict content security policy and should be using it without unsafe-inline to be effective, so on* attributes should mostly be forbidden instead of being special treated in gg.jte.html.OwaspHtmlTemplateOutput's writeTagAttributeUserContent.
The text was updated successfully, but these errors were encountered:
Right now it is not part of the default OwaspHtmlPolicy. As we don't know if/how users have set up a strict csp I'd suggest to leave the default as is. Advanced users can then add additional policies to fit their need.
Most projects should have a strict content security policy and should be using it without
unsafe-inline
to be effective, soon*
attributes should mostly be forbidden instead of being special treated ingg.jte.html.OwaspHtmlTemplateOutput
'swriteTagAttributeUserContent
.The text was updated successfully, but these errors were encountered: