The HTML card security model should be documented
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 1.1k
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Since the app renders AI-generated HTML, I would really like to know what DOMPurify allows, what gets stripped, whether inline styles are allowed, and how iframes or event handlers are handled. This is not just docs polish; it affects whether people feel safe enabling this feature.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing where AI-generated HTML cards are rendered and where the DOMPurify configuration is defined. Check the handling of allowed elements, stripped content, inline styles, iframes, and event handlers, then document the observed security model and how users can safely enable the feature.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- html
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100