Skip to content

Conversation

@hamishwillee
Copy link
Collaborator

Document.execCommand() with command insertHTML is an injection sink.

Given that this is just a small part of what the method does, and that the method is deprecated, I have added the disclaimer to the point where insertHTML is documented. The disclaimer does not link to a security considerations section, but instead points to the TT API overview. I think this is the right level.

Project tracking in #41507

@hamishwillee hamishwillee requested a review from a team as a code owner December 5, 2025 06:13
@hamishwillee hamishwillee requested review from wbamberg and removed request for a team December 5, 2025 06:13
@github-actions github-actions bot added Content:WebAPI Web API docs size/s [PR only] 6-50 LoC changed labels Dec 5, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Dec 5, 2025

Preview URLs

Copy link
Collaborator

@wbamberg wbamberg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 thanks, looks great.

@wbamberg wbamberg merged commit e593d32 into mdn:main Jan 1, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content:WebAPI Web API docs size/s [PR only] 6-50 LoC changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants