vulns.co
/
GKData.io MCP

World Wide Web Consortium · 1 min read

Trusted Types: typed sinks depend on trustworthy policy creation

Defines a browser-enforced boundary between ordinary strings and typed values accepted by injection-sensitive APIs. The underlying failure is allowing untrusted text to acquire executable interpretation. Policies centralize creation of accepted values; matching types preserve intended use, but do not independently establish that a policy's transformation is safe.

Open the reference Technical StandardReviewed 2026-10-03

How to use this reference

Editorial reasoning: review two invariants separately: sensitive consumers accept only policy-produced values, and each producer enforces an adequate trust contract. Minimize policy creation authority, keep policy dependencies reviewable and avoid global state silently changing decisions. The maintainer FAQ explains why sanitization must be consistently applied, rather than merely available in a library.

Before reading

  • JavaScript DOM data flow and Content Security Policy

Context and limits

  • The reviewed edition is a Working Draft, not a final W3C Recommendation. Krzysztof Kotowicz is its listed editor; Mike West is listed as former editor.
  • Unsafe policies can preserve DOM injection risk. The design does not isolate actively malicious first-party code or guard every DOM operation.
  • The FAQ distinguishes client-side sink controls from server-generated injection and complementary CSP defenses. Its 2021 browser-support discussion is historical and is not used as current compatibility evidence.

Sources and provenance

  1. Trusted Types World Wide Web Consortium · reviewed 2026-10-03
  2. Trusted Types publication history World Wide Web Consortium · reviewed 2026-10-03
  3. Trusted Types FAQ W3C Trusted Types project · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software