Document that filter_xss() must never be used in an attribute context

Created on 11 March 2015, about 10 years ago
Updated 26 March 2025, about 2 months ago

See https://docs.acquia.com/articles/using-filter-functions-intended-filterx...

We need to document at https://www.drupal.org/writing-secure-code and/or https://www.drupal.org/node/28984 that people should use drupal_clean_css_identifier() or similar, otherwise they get XSS issues.

📌 Task
Status

Postponed: needs info

Component

Missing documentation

Created by

🇦🇹Austria klausi 🇦🇹 Vienna

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024