HTML sanitization

To prevent certain security exploits, Looker restricts which HTML tags, HTML tag attributes, and CSS properties are allowed in the html parameter, in custom welcome emails, and in text tiles and tile notes in dashboards.

Looker strips any HTML elements that aren't supported from the rendered HTML. For example, the following HTML has unsupported HTML tags:

<div class="pretty"><badtag></badtag></div>

Looker will render this as:

<div class="pretty"></div>

As another example, the following HTML has unsupported HTML attributes:

<div class="pretty" badattr="uh-oh"></div>

Looker will render this as:

<div class="pretty"></div>

HTML sanitization is on by default and can't be edited.

Allowed HTML tags

Only certain HTML tags will be rendered in the browser. Any other tags will be stripped from rendered HTML.

Here is the list of HTML tags that Looker supports:

a

abbr

acronym

address

area

article

aside

audio

b

bdi

bdo

big

blockquote

br

button

canvas

caption

center

cite

code

col

colgroup

datalist

dd

del

details

dfn

dir

div

dl

dt

em

fieldset

figcaption

footer

h1

h2

h3

h4

h5

h6

header

ins

hr

i

img

kbd

label

legend

li

map

mark

menu

meter

nav

ol

output

p

pre

progress

q

s

samp

section

small

source

span

strike

strong

sub

summary

sup

table

tbody

td

tfoot

th

thead

time

tr

track

tt

u

ul

var

video

Allowed HTML tag attributes

Only certain HTML attributes will be rendered in the browser. Any other attributes will be stripped from rendered HTML. This also applies to the CSS properties for HTML style tags.

Here is the list of HTML attributes that Looker supports:

abbr

accept

accept-charset

accesskey

action

align

alt

autoplay

axis

border

cellpadding

cellspacing

char

charoff

charset

checked

cite

class

clear

color

cols

colspan

compact

controls

controlslist

coords

datetime

dir

disabled

enctype

for

frame

headers

height

href

hreflang

hspace

id

ismap

label

lang

longdesc

loop

loopcount

loopend

loopstart

maxlength

media

method

multiple

muted

name

nohref

noshade

nowrap

poster

preload

prompt

readonly

rel

rev

rows

rowspan

rules

scope

selected

shape

size

span

src

start

style

summary

tabindex

target

title

type

usemap

valign

value

vspace

width

xml:lang

Allowed CSS Properties for HTML style Tags

Here is the list of allowed CSS properties that Looker supports:

-moz-border-radius

-moz-border-radius-bottomleft

-moz-border-radius-bottomright

-moz-border-radius-topleft

-moz-border-radius-topright

-moz-box-shadow

-moz-outline

-moz-outline-color

-moz-outline-style

-moz-outline-width

-o-text-overflow

-webkit-border-bottom-left-radius

-webkit-border-bottom-right-radius

-webkit-border-radius

-webkit-border-radius-bottom-left

-webkit-border-radius-bottom-right

-webkit-border-radius-top-left

-webkit-border-radius-top-right

-webkit-border-top-left-radius

-webkit-border-top-right-radius

-webkit-box-shadow

azimuth

background

background-attachment

background-color

background-image (note that url is unsupported)

background-position

background-repeat

border

border-bottom

border-bottom-color

border-bottom-left-radius

border-bottom-right-radius

border-bottom-style

border-bottom-width

border-collapse

border-color

border-left

border-left-color

border-left-style

border-left-width

border-radius

border-right

border-right-color

border-right-style

border-right-width

border-spacing

border-style

border-top

border-top-color

border-top-left-radius

border-top-right-radius

border-top-style

border-top-width

border-width

box-shadow

caption-side

clear

color

cue

cue-after

cue-before

cursor

direction

display

elevation

empty-cells

float

font

font-family

font-size

font-stretch

font-style

font-variant

font-weight

height

image()

letter-spacing

line-height