remove xss leave some extra attribute
Bug #2002307 reported by
nattapong ratanasuwan
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
lxml |
New
|
Undecided
|
Unassigned |
Bug Description
from lxml.html.clean import Cleaner
cleaner = Cleaner(
style=True,
links=True,
add_
page_
safe_
)
raw_description = '<b onmouseover=
cleaner.
actual
```
<b testing>Test</b>\n
```
expect
```
<b>Test</b>
```
it should not have attribute `testing`
To post a comment you must log in.