Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is this project still maintained? #1

Open
flobernd opened this issue Feb 1, 2019 · 1 comment
Open

Is this project still maintained? #1

flobernd opened this issue Feb 1, 2019 · 1 comment

Comments

@flobernd
Copy link

flobernd commented Feb 1, 2019

Hi there,

do you still maintain this library?

I found a rather critical bug in the CSS validator implementation (validation does always fail for attributes having both literal values and regexes defined in the policy file) and was going to push you a pull request ...

Besides that there are some typos like AntiySamyPolicy instead of AntiSamyPolicy.

Best regards

@spassarop
Copy link

@flobernd if you are still concerned about this, I'm about to recover the .NET version of AntiSamy from OWASP's side and actually I was "forced" to use some Caner's code to make it work quickly, which must have the vulnerability you are mentioning. I'm not fully aware of the project's internals to understand where the issue is but I might know where it's located. If you want to help with this particular issue or eventually contribute to the other project, reach me at [email protected].

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants