Ver código fonte

update xss whitelist

Le Tan 1 ano atrás
pai
commit
05078a7857
2 arquivos alterados com 5 adições e 1 exclusões
  1. 0 1
      src/core/mainconfig.cpp
  2. 5 0
      src/data/extra/web/js/markdownit.js

+ 0 - 1
src/core/mainconfig.cpp

@@ -119,5 +119,4 @@ QString MainConfig::getVersion(const QJsonObject &p_jobj)
 void MainConfig::doVersionSpecificOverride()
 {
     // In a new version, we may want to change one value by force.
-    m_editorConfig->getMarkdownEditorConfig().m_protectFromXss = true;
 }

+ 5 - 0
src/data/extra/web/js/markdownit.js

@@ -215,6 +215,11 @@ class MarkdownIt extends VxWorker {
                                       whiteList: {
                                           input: ["class", "disabled", "type", "checked"],
                                           mark: ["class"],
+                                          font: ["color", "class"],
+                                          sub: ["class"],
+                                          sup: ["class"],
+                                          details: ["class"],
+                                          summary: ["class"],
                                       }
                                   });
                               });