diff --git a/owasp-java-html-sanitizer/src/main/java/org/owasp/html/HtmlPolicyBuilder.java b/owasp-java-html-sanitizer/src/main/java/org/owasp/html/HtmlPolicyBuilder.java index d5a5df05..05cf781d 100644 --- a/owasp-java-html-sanitizer/src/main/java/org/owasp/html/HtmlPolicyBuilder.java +++ b/owasp-java-html-sanitizer/src/main/java/org/owasp/html/HtmlPolicyBuilder.java @@ -967,9 +967,6 @@ public AttributeBuilder matching( */ @SuppressWarnings("synthetic-access") public HtmlPolicyBuilder globally() { - if (attributeNames.contains("style")) { - allowStyling(); - } return HtmlPolicyBuilder.this.allowAttributesGlobally( policy, attributeNames); } diff --git a/owasp-java-html-sanitizer/src/test/java/org/owasp/html/SanitizersTest.java b/owasp-java-html-sanitizer/src/test/java/org/owasp/html/SanitizersTest.java index 5ad6f501..4b4614f8 100644 --- a/owasp-java-html-sanitizer/src/test/java/org/owasp/html/SanitizersTest.java +++ b/owasp-java-html-sanitizer/src/test/java/org/owasp/html/SanitizersTest.java @@ -541,17 +541,6 @@ public static final void testOptionAllowsText() { pf.sanitize(input) ); } - - @Test - public static final void testStyleGlobally() { - PolicyFactory policyBuilder = new HtmlPolicyBuilder() - .allowAttributes("style").globally() - .allowElements("a", "label", "h1", "h2", "h3", "h4", "h5", "h6") - .toFactory(); - String input = "