Is <span style = ...> safe to disinfect?
I use a rich text editor (CKEditor), and I have the ability to allow users to create profiles that are displayed to other users.
Many of the attributes that CKEditor can control are lost when I show them as:
<%= sanitize(profile.body) %>
My question is: is it safe to allow the style attribute? This will display things like text color, size, background color, centering, indentation, etc. I just want to be sure that this will not allow the hacker to gain access to what I do not know about!
+5