Skip to main content

SANITIZE_ATTRIBUTES

Constant SANITIZE_ATTRIBUTES 

Source
pub const SANITIZE_ATTRIBUTES: &[&str];
Expand description

Attributes sanitize keeps on those tags: Rails’ safe list.

href, src and cite also need an http:, https:, mailto: or tel: URL (or a relative one). style and event handlers (onclick…) are never kept.

§Examples

assert!(ocre::security::SANITIZE_ATTRIBUTES.contains(&"href"));
assert!(!ocre::security::SANITIZE_ATTRIBUTES.contains(&"style"));