Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Links in href/src needs a protocol, but not in url(), why ? #273

Open
sky0matic opened this issue Jan 26, 2023 · 0 comments
Open

Links in href/src needs a protocol, but not in url(), why ? #273

sky0matic opened this issue Jan 26, 2023 · 0 comments

Comments

@sky0matic
Copy link

Hi there,

We notice that this library was removing links in href/src where there was no protocol.
However, the same doesn't apply to links in url() in style attributes on a background-image for example.

Why is that ?

Is there a security risk involving the need for a protocol ? If so, why does it not apply to url() too ?
If not, why is the protocol required in one place but not the other ?

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant