This vector shows which which html tags can clobber the credentials part of the URL, based on: portswigger.net/research/concealing-payloads-in-ur…
<$[data1] id="xx" $[data2]="https://x:x@x.com">if(xx.username==="x"){log('$[data1]:$[data2]')}<a:href id="xx" ="https://x:x@x.com"><area:href id="xx" ="https://x:x@x.com">