Skip to content

HtmlPolicy to forbid inline event handlers #20

@kelunik

Description

@kelunik

Most projects should have a strict content security policy and should be using it without unsafe-inline to be effective, so on* attributes should mostly be forbidden instead of being special treated in gg.jte.html.OwaspHtmlTemplateOutput's writeTagAttributeUserContent.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions