A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
-
Updated
Nov 3, 2025 - JavaScript
A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
Injects a trusted types policy into an HTML page to log all DOM sinks whenever HTML is written into the DOM.
A Symfony bundle providing web security features in the form of COOP, COEP, Fetch Metadata and Trusted types
Demo website showcasing Trusted Types for CSP
Small example with few endpoints used to test AdGuard AdBlocker compatibility with trusted types headers.
Demonstração prática do uso da API Trusted Types (CSP Level 3) e DOMPurify para evitar vulnerabilidades de Cross-Site Scripting (XSS) ao atribuir código inseguro ao DOM (ex: innerHTML).
A polyfill for the Trusted Types API
Add a description, image, and links to the trusted-types topic page so that developers can more easily learn about it.
To associate your repository with the trusted-types topic, visit your repo's landing page and select "manage topics."