Sanitizer: allowAttribute() method

Limited availability

This feature is not Baseline because it does not work in some of the most widely-used browsers.

The allowAttribute() method of the Sanitizer interface sets an attribute to be allowed on all elements when the sanitizer is used.

The method can be used with either an allow configuration or a remove configuration. If used with an allow configuration, the specified attribute is added to the attributes array. If used with a remove configuration, the attribute is removed from the removeAttributes array (if present).

Note that to allow/disallow attributes only on specific elements use Sanitizer.allowElement().

Syntax

js
allowAttribute(attribute)

Parameters

attribute

A string indicating the name of the attribute to be allowed globally on elements, or an object with the following properties:

name

A string containing the name of the attribute.

namespace Optional

A string containing the namespace of the attribute, which defaults to null.

Return value

true if the operation changed the configuration to allow the attribute, and false if the configuration already allowed the attribute.

Note that false might be returned if the internal configuration:

  • defines an attributes array and the attribute is already present (it does not need to be added again)
  • instead defines the removeAttributes array and the specified attribute is not present (and is hence already allowed)
  • dataAttributes is set true, but a data-* attribute is passed.

Examples

How to allow specific attributes on elements

This example shows how allowAttribute() is used to specify that an attribute is allowed on elements.

JavaScript

The code first creates a new Sanitizer object that initially allows no attributes. We then call allowAttribute() with the attributes title and mathcolor.

js
// Create an allow sanitizer
const sanitizer = new Sanitizer({
  attributes: [],
});

// Allow the "title" attribute
sanitizer.allowAttribute("title");
// Allow the "mathcolor" attribute
sanitizer.allowAttribute("mathcolor");

// Log the sanitizer configuration
let sanitizerConfig = sanitizer.get();
log(JSON.stringify(sanitizerConfig, null, 2));

Results

The final configuration is logged below. Note how both attributes are now added to the attributes list (other attributes will not be allowed on elements when the sanitizer is used).

Specifications

Specification
HTML Sanitizer API
# dom-sanitizer-allowattribute

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
allowAttribute
Chrome – Full support
Chrome 146 (Release date: 2026-03-10)
footnote Full support
Edge – Full support
Edge 146 (Release date: 2026-03-13)
footnote Full support
Firefox – Full support
Firefox 148 (Release date: 2026-02-24)
footnote Full support
Opera – Full support
Opera 130 (Release date: 2026-04-08)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 146 (Release date: 2026-03-10)
footnote Full support
Firefox for Android – Full support
Firefox for Android 148 (Release date: 2026-02-24)
footnote Full support
Opera Android – Full support
Opera Android 97 (Release date: 2026-04-16)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – No support
Samsung Internet
footnote No support
WebView Android – Full support
WebView Android 146 (Release date: 2026-03-10)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support