Fix: HtmlBlock sanitizer strips select/meter presentation attrs
size, low, high, and optimum were missing from PURIFY_CONFIG.ALLOWED_ATTR even though <select> and <meter> are already in ALLOWED_TAGS, so <select size="4"> rendered at default height and <meter low/high/optimum> lost its threshold-based gauge colouring. All four are pure presentation/semantic attributes with no URL/script/event-handler surface, so no security implication. Also regenerates the pinned pre-Task-25 output fixture: its source (html-block-test-body.html) already exercises size/low/high/optimum, so the byte-identity test's expected output legitimately changes to include them; verified the regenerated fixture's only diff from the prior one is those four attributes now surviving. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -107,12 +107,20 @@ const PURIFY_CONFIG = {
|
||||
// Task 24 additions.
|
||||
'colspan','rowspan','scope','headers','span','start','reversed',
|
||||
'type','value','name','placeholder','required','disabled','readonly',
|
||||
'checked','selected','multiple','min','max','step','minlength',
|
||||
'checked','selected','multiple','size','min','max','step','minlength',
|
||||
'maxlength','pattern','rows','cols','accept','action','method','for',
|
||||
'list','label','datetime','cite','lang','dir','role','srcset','media',
|
||||
'sizes','loading','controls','poster','loop','muted','autoplay',
|
||||
'preload','playsinline','kind','srclang','default','open','download',
|
||||
'hidden','contenteditable',
|
||||
// Bug fix: <select size="4">/<input size> and <meter low/high/optimum>
|
||||
// were still being stripped even though <select>/<meter> are already in
|
||||
// ALLOWED_TAGS -- only these four attribute names were missing here.
|
||||
// Effect: a multi-select rendered at default height instead of the
|
||||
// requested row count, and <meter> lost its threshold-based gauge
|
||||
// colouring. Pure presentation/semantic attributes -- no URL, no
|
||||
// script, no event-handler surface -- so no security weight added.
|
||||
'low','high','optimum',
|
||||
// SVG presentation attributes (explicit route -- see ALLOWED_TAGS
|
||||
// comment on the SVG tag list). Covers the fixture's <svg viewBox
|
||||
// role>/<rect>/<circle>/<text> block plus the common presentation
|
||||
|
||||
Reference in New Issue
Block a user