Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Sentry alert for upstream filter rules that use trusted-types scriptlet #958

Open
ShivanKaul opened this issue Aug 3, 2024 · 0 comments

Comments

@ShivanKaul
Copy link
Collaborator

We're going to be using the trusted-types scriptlet to counter YouTube ads: brave/adblock-lists#1933 (currently in Experimental, will be rolled out to all soon). Overriding Trusted Types is potentially dangerous, since the website puts the policy in place to prevent XSS attacks.

We don't currently use the trusted-types scriptlet anywhere else, but we should not accidentally inherit it from upstream. I propose checking this during the adblock lists packaging job. Note that we want to make sure we don't accidentally block the YT rule, so we should allow that one in particular.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant