dosubot[bot] commented on issue #36779:
URL: https://github.com/apache/superset/issues/36779#issuecomment-3678832784

   <!-- Answer -->
   In Superset 6.0, all HTML—including simple tags like <br/>—is stripped or 
escaped in deck.gl tooltips for security reasons. This is enforced by an HTML 
sanitizer that removes all tags, so even if you use the JavaScript tooltip 
generator, <br/> will not render as a line break but will appear as plain text. 
This is a deliberate security measure to prevent XSS and applies to all HTML 
tags in tooltips, not just complex or unsafe ones. There is currently no 
supported way to allow even simple HTML like <br/> in deck.gl tooltips, and 
this behavior is consistent across recent Superset versions [see 
details](https://github.com/apache/superset/pull/33791).
   
   If you need line breaks, you can use plain text separators (like \n or |), 
but these will not render as actual line breaks in the tooltip. Only Table 
charts have an option to render HTML in cells; this does not apply to deck.gl 
charts [see discussion](https://github.com/apache/superset/discussions/35000).
   
   
   <!-- Dosu Comment Footer -->
   *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).*
   
   ---
   <sup>How did I do? 
[Good](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=great_response)
 | 
[Irrelevant](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=irrelevant_answer)
 | 
[Incorrect](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=incorrect_sources)
 | 
[Verbose](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=too_verbose)
 | 
[Hallucination](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=hallucination)
 | [Report 
🐛](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=bug_report)
 | 
[Other](https://app.dosu.dev/response-feedback/35377d10-7851-47ca-9634-6fb41df1610d?feedback_type=other)</sup>
   
   [![Chat with 
Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/a28d3c7e-a9d3-459e-9fb6-3a6f9ff4f357/ask?utm_source=github)&nbsp;[![Open
 in 
Cursor](https://dosu.dev/dosu-in-cursor.svg)](https://cursor.com/link/prompt?text=In%20Superset%206.0%2C%20all%20HTML%E2%80%94including%20simple%20tags%20like%20%3Cbr/%3E%E2%80%94is%20stripped%20or%20escaped%20in%20deck.gl%20tooltips%20for%20security%20reasons.%20This%20is%20enforced%20by%20an%20HTML%20sanitizer%20that%20removes%20all%20tags%2C%20so%20even%20if%20you%20use%20the%20JavaScript%20tooltip%20generator%2C%20%3Cbr/%3E%20will%20not%20render%20as%20a%20line%20break%20but%20will%20appear%20as%20plain%20text.%20This%20is%20a%20deliberate%20security%20measure%20to%20prevent%20XSS%20and%20applies%20to%20all%20HTML%20tags%20in%20tooltips%2C%20not%20just%20complex%20or%20unsafe%20ones.%20There%20is%20currently%20no%20supported%20way%20to%20allow%20even%20simple%20HTML%20like%20%3Cbr/%3E%20in%20deck.gl%20tooltips%2C%20and%20thi
 
s%20behavior%20is%20consistent%20across%20recent%20Superset%20versions%C2%A0%5Bsee%20details%5D%28https%3A//github.com/apache/superset/pull/33791%29.%0A%0AIf%20you%20need%20line%20breaks%2C%20you%20can%20use%20plain%20text%20separators%20%28like%20%5Cn%20or%20%7C%29%2C%20but%20these%20will%20not%20render%20as%20actual%20line%20breaks%20in%20the%20tooltip.%20Only%20Table%20charts%20have%20an%20option%20to%20render%20HTML%20in%20cells%3B%20this%20does%20not%20apply%20to%20deck.gl%20charts%C2%A0%5Bsee%20discussion%5D%28https%3A//github.com/apache/superset/discussions/35000%29.)&nbsp;[![Join
 
Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share
 on 
X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/apache/superset/issues/36779)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to