浏览代码

fix: allow custom protocols

Konstantinos Kaloutas 3 年之前
父节点
当前提交
8dfab3bd13
共有 1 个文件被更改,包括 2 次插入1 次删除
  1. 2 1
      src/main/frontend/security.cljs

+ 2 - 1
src/main/frontend/security.cljs

@@ -2,7 +2,8 @@
   "Provide security focused fns like preventing XSS attacks"
   (:require ["dompurify" :as DOMPurify]))
 
-(def sanitization-options (clj->js {:ADD_TAGS ["iframe"]}))
+(def sanitization-options (clj->js {:ADD_TAGS ["iframe"]
+                                    :ALLOW_UNKNOWN_PROTOCOLS true}))
 
 (defn sanitize-html
   [html]