Hacker News new | past | comments | ask | show | jobs | submit login

> Also, it may be a good idea to sanitize the comment.body_html. That seems XSS abuseable.

GitHub handles sanitizing comment HTML automatically. They use a fairly strict[1] whitelist of tags/attributes that are allowed through. Anything that's not allowed gets escaped.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: