Summary:
"Sanitize While Parsing" consumes the Sanitizer API's config during HTML parsing steps, rather than iterating over a reified tree. This feature has been developed under the `dom.security.sanitizer.while-parsing` feature flag and can be enabled in current nightly builds.
The implementation is at the stage where I intend to enable it in Nightly only builds (
https://bugzilla.mozilla.org/show_bug.cgi?id=2070497), so that we can compare it to the default implementation (which sanitizes after parsing). I intend to enable it in Nightly builds as soon as possible to allow us the widest window for catching regressions or bugs.
Once the 159 release cycle has started (September 24) I intend to turn this feature on by default on all platforms, meaning it will (barring any major issues) ship by default in 159 (October 27).
As usual, if any issues arise, please let me know and I will happily roll the flag back.
Happy (sanitized) browsing!
Bug to turn on by default:
Standard:
Intent to Prototype Thread:
This feature was previously discussed in this "Intent to Prototype" thread:
TAG Review:
N/A