Sanitizer API: HTML setter methods
This is an extension of the proposal in #1336 to cover the new HTML setters and streaming setter methods, and the integration with trusted types.
The Sanitizer API is providing a new method to modify HTML without causing XSS, which is one of the most prevalent security vulnerabilities in the world. In order for developers to be able to depend on these features it's necessary for them to be reliable cross-browser.
Note that, although this feature is an unmerged PR at the time of writing, we are confident it will be merged in plenty of time for Interop.
Discussion on GitHub (6)
Note: scope updated to exclude the streaming setter APIs.
Related: #1465
CC @otherdaniel.
Dupe of #1336? You can't really use one without the other.
Well you can implement Sanitizer API with just
setHTML(Firefox does this, as did Chrome originally, but we're about to launch these), without these new additions. So while I agree #1336 is needed first, I don't think implementing #1336 implies this will be implemented as well.The original post does start with "This is an extension of the proposal in https://github.com/web-platform-tests/interop/issues/1336..."
So currently we're tracking these as two separate feature ids: sanitizer and html-setters (three if you include html-streaming-setters). So I think it's not unreasonable to track as two (very related!) interop proposals. While I'd love to see both implemented, I don't know if combining them them would risk #1336 getting rejected due to the scope being too big/these being too new, if these are insisted upon being part of that?
I'm not against them staying separate as long as it's absolutely clear what it would mean for Interop to take on one but not the other.