# How to define my allowlist for SVG attributes? (K3.6, Sane class)

**URL:** <https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999>\
**Category:** Questions\
**Tags:** v3\
**Created:** [November 20, 2021, 5:51pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999 "2021-11-20T17:51:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sebastiangreger](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/sebastiangreger/32/16176_2.png) [@sebastiangreger](https://forum.getkirby.com/u/sebastiangreger)\
**Post date:** [November 20, 2021, 5:51pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/1 "2021-11-20T17:51:48Z")

</div>

Kirby 3.6 throws an error `The "viewbox" attribute (line 1) is not allowed: Not included in the global allowlist` (from: _/src/Toolkit/Dom.php_, line 741; _sanitizeAttr_ function) when I try to do the following:

```php
// attach the SVG image to the page
$svgfile = $page->createFile([
    'filename' => 'track.svg',
    'source' => $tempfile,
    'template' => 'tracksvg',
]);

```

The SVG file is stored under path `$tempfile` and looks like this:

```svg
<svg xmlns="http://www.w3.org/2000/svg" version="1.1" viewbox="0 0 1000 1000">
<g>
<path d="M 893 19 893 19 894 19 893 20 892 22 887 26" style="fill:none;stroke:black"/>
</g>
</svg>

```

Since my solution worked fine in 3.5, I assume this is related to the new sanitization features of the `Sane` class mentioned in the release notes, but I can’t figure out how to declare `viewbox` a permitted attribute for SVG files. Is this “allowlist” feature already documented somewhere? Thank you 🙂

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [November 20, 2021, 6:19pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/2 "2021-11-20T18:19:39Z")

</div>

Hm, the `viewbox` attribute **is** in the list of `$allowedAttrs`, see `/kirby/src/Sane/Svg.php`, 🤔.

But that probably doesn’t count as the global allowlist? Seems a bit weird.

Ping @lukasbestle

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [November 20, 2021, 7:09pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/3 "2021-11-20T19:09:35Z")

</div>

The attribute is called `viewBox` with a capital B. Since XML is case-sensitive, the `Sane` and `Dom` classes also handle the allowed attributes case-sensitively. Kirby 3.5 used `in_array()` for this, which also treats the items case-sensitively, so as far as I can tell there was no change to this behavior.

What I wonder is: Does `viewbox` with a lowercase B actually work? Browsers and SVG editors should ignore it as it uses the wrong case, but it could be that some implementations still support it for compatibility.

To answer your original question: You can add additional allowed attributes to the global allowlist in `Kirby\Sane\Svg::$allowedAttrs` or you can allow it for specific tags with `Kirby\Sane\Svg::$allowedTags['svg'] = ['viewbox']`.

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [November 20, 2021, 7:44pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/4 "2021-11-20T19:44:58Z")

</div>

@lukasbestle Thanks, your eyes are definitely better than mine!

---

<div class="post-metadata">

**Author:** ![sebastiangreger](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/sebastiangreger/32/16176_2.png) [@sebastiangreger](https://forum.getkirby.com/u/sebastiangreger)\
**Post date:** [November 21, 2021, 10:20am UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/5 "2021-11-21T10:20:35Z")

</div>

> [@lukasbestle](#):
>
> The attribute is called `viewBox` with a capital B.

Such an obvious mistake, yet so hard to spot – thank you for pointing it out! …talk about not seeing the wood for the trees 🙈

> [@lukasbestle](#):
>
> What I wonder is: Does `viewbox` with a lowercase B actually work?

Not empirically valid observations, but I at least hadn’t noticed any issues with those SVGs (which `Sane`, up to K3.5.7.1, indeed never complained about before; that script churned out hundreds of them per year). Will of course fix them asap, as that is not valid SVG markup.

> [@lukasbestle](#):
>
> You can add additional allowed attributes to the global allowlist in `Kirby\Sane\Svg::$allowedAttrs` or you can allow it for specific tags with `Kirby\Sane\Svg::$allowedTags['svg'] = ['viewbox']` .

Thank you, great to know!

…in case anybody else ever ends up here via search: I just recalled that you provided somewhat related tips on configuring the `Sane` class over on a [Github issue on GPX files](https://github.com/getkirby/kirby/issues/3433#issuecomment-864851723) a while back.

---

<div class="post-metadata">

**Author:** ![neville](https://avatars.discourse-cdn.com/v4/letter/n/858c86/32.png) [@neville](https://forum.getkirby.com/u/neville)\
**Post date:** [November 10, 2024, 2:45pm UTC](https://forum.getkirby.com/t/how-to-define-my-allowlist-for-svg-attributes-k3-6-sane-class/23999/6 "2024-11-10T14:45:29Z")

</div>

It’s not obvious from the replies in this thread exactly how to define an allowlist for SVG attributes. So I’m posting this here to help out others, especially those less experienced with PHP.

Update your index.php file (located in your project folder) with this line (underneath the require bootstrap) for one SVG attribute:

```php
\Kirby\Sane\Svg::$allowedAttrs[] = 'myAttribute';

```

Or for multiple attributes, use an array:

```php
\Kirby\Sane\Svg::$allowedTags['svg'] = array_merge(\Kirby\Sane\Svg::$allowedAttrs, ['myAttribute', 'anotherAttribute']);

```

Example for one attribute  
index.php

```php
<?php

require 'kirby/bootstrap.php';

\Kirby\Sane\Svg::$allowedAttrs[] = 'myAttribute';

echo (new Kirby)->render();

```

Works in Kirby 4

Credit to @bnomei on Discord for the code snippet and help 🙂
