This vector shows which which html tags can clobber the credentials part of the URL, based on: https://portswigger.net/research/concealing-payloads-in-url-credentials
<$[data1] id="xx" $[data2]="https://x:x@x.com">if(xx.username==="x"){log('$[data1]:$[data2]')}<a:href id="xx" ="https://x:x@x.com"><area:href id="xx" ="https://x:x@x.com">