Skip to content
Discussion options

You must be logged in to vote

Hi @DavideArgellati ,

As the notification content comes from a safe source, namely your server, we do not sanitise the notification.content in our react sdk. We simply render the HTML that you've sent to us. If we were to sanitise, you'd lose the functionality of adding javascript code to your notifications.

In the past, that has been different, but we believe that the flexibility to add javascript - from a controlled source - out-weights the benefit of sanitising every message. If you need to sanitise the messages because they're user generated, then you'd need to do this on your side, preferably on your server at the moment you create the notification.

Alternatively, you can provide a c…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@DavideArgellati
Comment options

Answer selected by smeijer
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Questions
Labels
None yet
2 participants