[wp-meta] [Making WordPress.org] #1616: Remote CSS: Allow data URIs in CSS properties

Making WordPress.org noreply at wordpress.org
Thu Apr 18 17:51:53 UTC 2019

#1616: Remote CSS: Allow data URIs in CSS properties
 Reporter:  ryelle                   |       Owner:  (none)
     Type:  defect                   |      Status:  assigned
 Priority:  normal                   |   Milestone:
Component:  WordCamp Site & Plugins  |  Resolution:
 Keywords:  has-patch                |

Comment (by iandunn):

 It doesn't seem like we have any new information to give us confidence
 that it's safe to use them in this way. If someone can provide some,
 though, then we can definitely consider it.

 Give how fundamentally broken SVGs are from a security perspective, I
 think the bar for what would give me confidence is fairly high. e.g., an
 example of a major project like Drupal doing it, or an authoritative
 security researcher like Mario Heiderich saying that it's safe.

Ticket URL: <https://meta.trac.wordpress.org/ticket/1616#comment:10>
Making WordPress.org <https://meta.trac.wordpress.org/>
Making WordPress.org

More information about the wp-meta mailing list