Skip to content

[css-contain] Security/Privacy considerations of css-contain misuse? #1376

@svgeesus

Description

@svgeesus

From Ralph Swick, on the css-contain CR transition call:

Security considerations should include something about risks and counter-measures if a bad actor misuses these new features; e.g. to alter (and misrepresent) what is rendered to the user.

Would it be appropriate to have some test cases that misuse the features and test what the implementation does in those situations?

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions