Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[misc] run user comment through bleach #416

Merged
merged 1 commit into from
Jan 27, 2025
Merged

Conversation

leduythuccs
Copy link
Contributor

@leduythuccs leduythuccs commented Jan 27, 2025

Description

Previously, the script <img src=1 href=1 onerror="alert(123)"></p> will got XSS. To fix that, we have two options, one is to update our markdown2 fork (at: https://github.com/VNOI-Admin/python-markdown2), the other is using bleach.

It has been too long since i last touch the markdown2, i couldn't recall why i made those fix in the fork, so better leave it as it for now. Updating the settings is more easy, and no need to reinstall requirements!

What

Update the markdown style settings!

@leduythuccs leduythuccs merged commit d8263f0 into master Jan 27, 2025
6 checks passed
@leduythuccs leduythuccs deleted the thuc/validate-user-style branch January 27, 2025 06:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant