@@ -49,8 +49,8 @@ class HTMLSanitizerMixin(object):
4949'lang' ,'list' ,'longdesc' ,'loop' ,'loopcount' ,'loopend' ,
5050'loopstart' ,'low' ,'lowsrc' ,'max' ,'maxlength' ,'media' ,'method' ,
5151'min' ,'multiple' ,'name' ,'nohref' ,'noshade' ,'nowrap' ,'open' ,
52- 'optimum' ,'pattern' ,'ping' ,'point-size' ,'prompt ' ,'pqg' ,
53- 'radiogroup' ,'readonly' ,'rel' ,'repeat-max' ,'repeat-min' ,
52+ 'optimum' ,'pattern' ,'ping' ,'point-size' ,'poster ' ,'pqg' , 'preload ' ,
53+ 'prompt' , ' radiogroup' ,'readonly' ,'rel' ,'repeat-max' ,'repeat-min' ,
5454'replace' ,'required' ,'rev' ,'rightspacing' ,'rows' ,'rowspan' ,
5555'rules' ,'scope' ,'selected' ,'shape' ,'size' ,'span' ,'src' ,'start' ,
5656'step' ,'style' ,'summary' ,'suppress' ,'tabindex' ,'target' ,
@@ -97,7 +97,7 @@ class HTMLSanitizerMixin(object):
9797'xml:base' ,'xml:lang' ,'xml:space' ,'xmlns' ,'xmlns:xlink' ,'y' ,
9898'y1' ,'y2' ,'zoomAndPan' ]
9999
100- attr_val_is_uri = ['href' ,'src' ,'cite' ,'action' ,'longdesc' ,
100+ attr_val_is_uri = ['href' ,'src' ,'cite' ,'action' ,'longdesc' ,'poster' ,
101101'xlink:href' ,'xml:base' ]
102102
103103svg_attr_val_allows_ref = ['clip-path' ,'color-profile' ,'cursor' ,'fill' ,