Page MenuHomePhabricator

Permit hidden attribute in Sanitizer
Open, Needs TriagePublic


I think we should allow setting [[ | hidden attribute ]] on elements from wiki code. It is a stable part of HTML5 spec that shouldn’t have any security holes as it’s just applying display: none; styling from a browser. Given that we are not disallowing people from writing style="display:none;", it doesn’t make sense to disallow writing, essentially, a shorter form of this.

My use case (and how I found it):

Relevant code:$1760

This is similar to T145002 / T204618

Event Timeline

Jcross subscribed.

Upon review, Security Team is untagging as we will not be working on this ticket.