Add allowedTags to HTMLContentTransform request #5347
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Changelog Entry
Added
request.allowedTags
Description
Added
request.allowedTags
to enable custom elements story through HTML content transform middleware.Design
Background: the HTML sanitizer is the very last function in the HTML content transform middleware.
One story of HTML content transform middleware is to convert, say,
<a>
into<my-link>
.This PR enables the middleware to allowlist additional tag names for the HTML sanitizer. It can also enable denylist and observe the allowed tag names.
Specific Changes
HTMLContentTransformMiddleware
to include newallowedTags
useTransformHTMLContent()
hookCHANGELOG.md
I have updated documentationReview Checklist
Accessibility reviewed (tab order, content readability, alt text, color contrast)Browser and platform compatibilities reviewedCSS styles reviewed (minimal rules, noz-index
)Documents reviewed (docs, samples, live demo)Internationalization reviewed (strings, unit formatting)package.json
andpackage-lock.json
reviewedSecurity reviewed (no data URIs, check for nonce leak)