You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"Get Trusted Type compliant string" [1] invokes "Should sink type mismatch violation be blocked by Content Security Policy?" [2].
The latter checks for a match of the sinkGroup in step 2.3, which refers to [3] which contains "'sink'".
mbrodesser-Igalia
changed the title
"Get Trusted Type compliant string" is called with "sink" instead of "'sink'"
"Get Trusted Type compliant string" is called with "script" instead of "'script'"
Aug 26, 2024
koto
added a commit
to koto/trusted-types
that referenced
this issue
Nov 5, 2024
E.g. from https://html.spec.whatwg.org/#the-insertadjacenthtml()-method.
"Get Trusted Type compliant string" [1] invokes "Should sink type mismatch violation be blocked by Content Security Policy?" [2].
The latter checks for a match of the sinkGroup in step 2.3, which refers to [3] which contains "'sink'".
[1] https://w3c.github.io/trusted-types/dist/spec/#get-trusted-type-compliant-string-algorithm
[2] https://w3c.github.io/trusted-types/dist/spec/#abstract-opdef-should-sink-type-mismatch-violation-be-blocked-by-content-security-policy
[3] https://w3c.github.io/trusted-types/dist/spec/#trusted-types-sink-group
The text was updated successfully, but these errors were encountered: