How to use this reference
Editorial reasoning: review two invariants separately: sensitive consumers accept only policy-produced values, and each producer enforces an adequate trust contract. Minimize policy creation authority, keep policy dependencies reviewable and avoid global state silently changing decisions. The maintainer FAQ explains why sanitization must be consistently applied, rather than merely available in a library.
Before reading
- JavaScript DOM data flow and Content Security Policy
Context and limits
- The reviewed edition is a Working Draft, not a final W3C Recommendation. Krzysztof Kotowicz is its listed editor; Mike West is listed as former editor.
- Unsafe policies can preserve DOM injection risk. The design does not isolate actively malicious first-party code or guard every DOM operation.
- The FAQ distinguishes client-side sink controls from server-generated injection and complementary CSP defenses. Its 2021 browser-support discussion is historical and is not used as current compatibility evidence.
Sources and provenance
- Trusted Types World Wide Web Consortium · reviewed 2026-10-03
- Trusted Types publication history World Wide Web Consortium · reviewed 2026-10-03
- Trusted Types FAQ W3C Trusted Types project · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.