Security concerns about using bypassSecurityTrustResourceUrl() to display base64 images in Angular

Viewed 335

I have a working Angular application displaying base64 images in HTML using : this.sanitizer.bypassSecurityTrustResourceUrl("data:image/jpeg;base64,...")

However, bypassing this security opens a door for XSS attacks such as explained in the Angular documentation.

Besides, an external company paid to find security issues in my code found those lines of code inacceptable and asked me to fix it.

Because I am not able to sanitize this base64 string image using this.sanitizer.sanitize() method, and because I cannot find any other way to do it on the internet, I would like to ask you how I could achieve my goal without exposing my application to XSS security issues.

Is there any other way to (filter, escape, validate) sanitize a base64 image in order to use it in an <img> tag ?

Any help or advice would be greatly appreciated !

0 Answers
Related