Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Can safehtml support custom attributes like one that HTMX requires?

Open
#11 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
go
Domain
security

Research direction

Start by reading the sanitization contexts elementSpecificAttrValSanitizationContext, globalAttrValSanitizationContext, and elementContentSanitizationContext mentioned in the issue. Determine whether a string-literal-based custom-attribute API can preserve the package's safety guarantees for HTMX attributes such as hx-get; done means the API and its safety behavior are defined and verified.

Written by the indexing model from the issue text.

Description

I started a personal web project and decided to use this package rather than the default html/template as it seems like a responsible thing to do, but I am running into an error that I cannot get around without forking the package:

html/template:my.template.html: cannot escape action {{.Url}}: actions 
must not occur in the "hx-get" attribute value context of a "li" element

From reading the code is seems that you have hardcoded all potential element-attribute combinations into elementSpecificAttrValSanitizationContext and globalAttrValSanitizationContext/elementContentSanitizationContext and thus the hx-get attribute is disallowed, right?

Is there any reason why it would be unsafe to add a method that allows adding attributes to be considered valid, assuming they are adding using string literals passed to the method that would add them?

If not, seems like a really easy enhancement I could add and create a PR for? Would that be something you would consider allowing?

Dominant language
Go
Stars
380
Forks
23
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from google/safehtml

All issues in google/safehtml

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.