Browse Source

fix: remove attributes and protocols

Konstantinos Kaloutas 3 years ago
parent
commit
60790763dd
1 changed files with 1 additions and 8 deletions
  1. 1 8
      src/main/frontend/security.cljs

+ 1 - 8
src/main/frontend/security.cljs

@@ -2,14 +2,7 @@
   "Provide security focused fns like preventing XSS attacks"
   (:require ["dompurify" :as DOMPurify]))
 
-(def sanitization-options (clj->js {:ADD_TAGS ["iframe"]
-                                    :ALLOW_UNKNOWN_PROTOCOLS true
-                                    :ADD_ATTR ["allow"
-                                               "src"
-                                               "allowfullscreen"
-                                               "frameborder"
-                                               "scrolling"
-                                               "target"]}))
+(def sanitization-options (clj->js {:ADD_TAGS ["iframe"]}))
 
 (defn sanitize-html
   [html]