Skip to main content

Build Status

cssfilter.py extracted from reddit’s source code.

This library allows you to filter “unsafe” css from your users.

This library requires attribution!:

When using this library, reddit requires you to put the following information in the splash or the “about” section of your application.

EXHIBIT B. Attribution Information

Attribution Copyright Notice: Copyright (c) 2006-2015 reddit Inc. All Rights Reserved.

Attribution Phrase (not exceeding 10 words): Powered by reddit

Attribution URL: http://code.reddit.com

Graphic Image as provided in the Covered Code: http://code.reddit.com/reddit_logo.png

Info

Parse and validate a safe subset of CSS.

The goal of this validation is not to ensure functionally correct stylesheets but rather that the stylesheet is safe to show to downstream users. This includes:

  • not generating requests to third party hosts (information leak)

  • xss via strange syntax in buggy browsers

Beyond that, every effort is made to allow the full gamut of modern CSS.

How to use

import reddit_cssfilter.cssfilter
cssfilter.validate_css(stylesheet, images)

Validate and re-serialize the user submitted stylesheet.

images is a mapping of subreddit image names to their URLs. The re-serialized stylesheet will have %%name%% tokens replaced with their appropriate URLs.

The return value is a two-tuple of the re-serialized (and minified) stylesheet and a list of errors. If the list is empty, the stylesheet is valid.

Licence

Copyright (c) 2006-2015 reddit Inc. All Rights Reserved.

Common Public Attribution License Version 1.0 (CPAL)

The full license is available here: reddit Inc. Common Public Attribution License Version 1.0 (CPAL).

Release files for reddit-cssfilter 1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for reddit-cssfilter 1.2
File Size Uploaded
reddit-cssfilter-1.2.tar.gz 7.7 kB Details

Release files / reddit-cssfilter-1.2.tar.gz

Download URL reddit-cssfilter-1.2.tar.gz
Size 7.7 kB
Tags Source
SHA-256 checksum
How to use checksums
d058ad2597d10dc482eda2445ab5c70a6b0cd9c3a96df487035ba5db23f860ec
BLAKE2b-256 checksum
How to use checksums
40ebc651584fb3d335f14c757bdaed7830202b58ff3af385c2785ea9cc236f56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

1.2 This release

1 release file

1.1

1 release file

1.0

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page