The Caja UrlPolicy document has a nice list of HTML attributes that can
be rewritten.

http://code.google.com/p/google-caja/wiki/UrlPolicy

On 2010/07/16 13:38:45, Kuntal Loya wrote:
The AbsolutePathReferenceVisitor and the ProxyingContentVisitor should
bypass
the embed and the object tags for now.
The src attribute of input and background attribute of body should be
rewritten.



http://codereview.appspot.com/1806044/show

Reply via email to