Problem/Motivation
Xss::attributes() contains a list of dangerous attributes or prefixes:
in_array($attribute_name, ['style', 'srcdoc']) ||
str_starts_with($attribute_name, 'on') ||
str_starts_with($attribute_name, 'data-hx') ||
str_starts_with($attribute_name, 'hx') ||
str_starts_with($attribute_name, '-') ||
Contrib modules sometimes have their own logic for detecting dangerous attributes and they have to duplicate these rules.
This means that if we had a new dangerous attribute (this was done for SA-CORE-2026-011 for example), they won't automatically benefit from it.
Steps to reproduce
Proposed resolution
Maybe move this logic to a method like this:
Xss::isAttributeDangerous($attribute_name)
Remaining tasks
User interface changes
Introduced terminology
API changes
Data model changes
Release notes snippet
Comments