Edit: Is there a server-side whitelist for html tags or is it all on the client-side? I've heard of people finding ways to escape script tags so they don't get detected on the front end, but they get turned into script tags on the backend and can execute.
Jump in the discussion.
No email address required.
What's "data-bs-original-name" do?
Jump in the discussion.
No email address required.
no idea why i added this to the whitelist lol, removed
Jump in the discussion.
No email address required.
Hey can you add script to the whitelist?
Edit: Is there a server-side whitelist for html tags or is it all on the client-side? I've heard of people finding ways to escape script tags so they don't get detected on the front end, but they get turned into script tags on the backend and can execute.
Jump in the discussion.
No email address required.
yeah we have a content security policy for this reason haha
Jump in the discussion.
No email address required.
OK cool!
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context