A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
-
Updated
Nov 3, 2025 - JavaScript
A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
Injects a trusted types policy into an HTML page to log all DOM sinks whenever HTML is written into the DOM.
A Symfony bundle providing web security features in the form of COOP, COEP, Fetch Metadata and Trusted types
Demonstração prática do uso da API Trusted Types (CSP Level 3) e DOMPurify para evitar vulnerabilidades de Cross-Site Scripting (XSS) ao atribuir código inseguro ao DOM (ex: innerHTML).
Small example with few endpoints used to test AdGuard AdBlocker compatibility with trusted types headers.
Demo website showcasing Trusted Types for CSP
A polyfill for the Trusted Types API
Add a description, image, and links to the trusted-types topic page so that developers can more easily learn about it.
To associate your repository with the trusted-types topic, visit your repo's landing page and select "manage topics."