Page MenuHomePhabricator

Added `-` to the whitelist for CSS rules
ClosedPublic

Authored by jcox on Sep 8 2016, 8:25 PM.
Tags
None
Referenced Files
F18768337: D16519.id.diff
Wed, Oct 8, 3:04 AM
F18764350: D16519.diff
Tue, Oct 7, 5:34 AM
F18733401: D16519.id.diff
Tue, Sep 30, 10:33 PM
F18616255: D16519.diff
Sep 14 2025, 4:47 PM
F18094139: D16519.diff
Aug 7 2025, 9:58 PM
F18091332: D16519.id.diff
Aug 6 2025, 9:09 PM
F18089897: D16519.id39756.diff
Aug 6 2025, 1:14 PM
F18082869: D16519.diff
Aug 5 2025, 7:42 AM

Details

Summary

Fixes T11567. This way people can use things like sans-serif and -webkit-small-control for their "monospaced" font

Test Plan

I added the hyphen to the regex then was able to set my Monospaced Font to be anything with a hyphen in it.

I also tried to break it pretty extensively, but couldn't find anything that would let me write malicious CSS or JS.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

jcox retitled this revision from to Added `-` to the whitelist for CSS rules.
jcox updated this object.
jcox edited the test plan for this revision. (Show Details)
jcox edited edge metadata.
This revision is now accepted and ready to land.Sep 8 2016, 8:26 PM
This revision was automatically updated to reflect the committed changes.