Skip to content

Add warning for html.script #924

Closed
@Archmonger

Description

@Archmonger

Current Situation

Currently, there is no documented warnings for the potential of XSS attacks when using html.script

Proposed Actions

We should add a disclaimer to warn users not to use raw user inputs (from any untrusted data source) within the script contents to avoid XSS attacks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    flag-good-first-issueA well defined and self-contained task.priority-3-lowMay be resolved one any timeline.type-docsAbout changes and updates to documentation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions