Hey all,
I'll jump in here and ask something I've been stuck on for a while.
I've been working on this custom visual to display html formatted paragraphs so that I can pass formatting inline with value data into a custom visual for long text, which is useful for text fields.
The gitHub Repo is here:
https://github.com/mjbellomo/pbvizHtmlVisual
For simplicity's sake I'd like to be able to be able to set the innerHTML = dataView.Table.Rows.ToString() but I'm concious of the vulnerabilites intruduced by doing so, short of adding in all of the various format options into the format panel individually.
Thoughts?
Hello @mjbellomo,
Thanks for your feedback.
I think that you can use js-xss to prevent a XSS injection.
Ignat Vilesov,
Software Engineer
Microsoft Power BI Custom Visuals
Join us for a free, hands-on Microsoft workshop led by women trainers for women where you will learn how to build a Dashboard in a Day!