W3C home > Mailing lists > Public > public-webappsec@w3.org > October 2018

[CSP3] "style-src 'none';" and presentation hints/mapped attributes

From: Jonathan Watt <jwatt@jwatt.org>
Date: Wed, 3 Oct 2018 12:09:44 +0100
To: public-webappsec@w3.org
Message-ID: <add52fe1-9eba-66ec-556f-f4245cb05186@jwatt.org>
I don't see much previous discussion (only [1]) about attributes that are
treated as presentation hints and mapped into style[2][3] and how they should be
treated when the 'style' attribute is blocked.

It would seem to make sense to block mapped attributes in this case for HTML,
but it would break most SVG content.

1. https://lists.w3.org/Archives/Public/public-webappsec/2012Nov/0019.html
2.
https://html.spec.whatwg.org/#the-css-user-agent-style-sheet-and-presentational-hints
3. https://svgwg.org/svg2-draft/single-page.html#attindex-PresentationAttributes
Received on Wednesday, 3 October 2018 11:10:10 UTC

This archive was generated by hypermail 2.3.1 : Wednesday, 3 October 2018 11:10:10 UTC