Skip to content

Conversation

@ThisIsMissEm
Copy link
Contributor

@ThisIsMissEm ThisIsMissEm commented Sep 29, 2025

This was originally noted in #18 and #19 and changed in #33, however prohibiting just data: and javascript: would not be a sufficient security measure, as there are other URI schemes that are unsafe, such as vbscript: and shortcuts: (apple shortcuts).

Interestingly, I know vbscript: exists, however, it is not registered with IANA: https://www.iana.org/assignments/uri-schemes/uri-schemes.xhtml

@ThisIsMissEm
Copy link
Contributor Author

cc @matthieusieben

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant