Intent to prototype: Sanitize While Parsing

71 views
Skip to first unread message

Keith Cirkel

unread,
Aug 12, 2026, 4:28:56 AM (yesterday) Aug 12
to dev-pl...@mozilla.org
Summary:

Change the consumption steps of the Sanitizer API so that it sanitizes during parse steps, rather than the reified tree.

The motivation for this is to address some issues around the non-parser sanitization steps which prevent sanitizing scoped registries and declarative shadow roots.

By and large this change should not be web observable, modulo the above two points. Scoped Registries has not shipped yet, and this is one way we can unblock them from shipping.

Bug:

Specification:

Standards Body:
WHATWG

Platform Coverage:
all.

Preference:
`dom.security.sanitizer.while_parsing`

DevTools Bug:
N/A

Extensions Bug:
N/A

Use Counter:
I don't think this is necessary but happy to add one if people think it would be useful.

Standards-Positions Discussion:

Other Browsers:
- Blink: Shipped 153 (sub-feature of https://chromestatus.com/feature/5054329641893888)
- WebKit: Positive of the overall feature.


Reply all
Reply to author
Forward
0 new messages