Browse Source

update xss whitelist

Le Tan 1 year ago
parent
commit
78de724757
1 changed files with 9 additions and 7 deletions
  1. 9 7
      src/data/extra/web/js/markdownit.js

+ 9 - 7
src/data/extra/web/js/markdownit.js

@@ -213,13 +213,15 @@ class MarkdownIt extends VxWorker {
                               () => {
                                   this.mdit.use(window.markdownItXSS, {
                                       whiteList: {
-                                          input: ["class", "disabled", "type", "checked"],
-                                          mark: ["class"],
-                                          font: ["color", "class"],
-                                          sub: ["class"],
-                                          sup: ["class"],
-                                          details: ["class"],
-                                          summary: ["class"],
+                                          input: ["style", "class", "disabled", "type", "checked"],
+                                          mark: ["style", "class"],
+                                          font: ["style", "color", "class"],
+                                          sub: ["style", "class"],
+                                          sup: ["style", "class"],
+                                          details: ["style", "class"],
+                                          summary: ["style", "class"],
+                                          ins: ["style", "class"],
+                                          span: ["style", "class"],
                                       }
                                   });
                               });