Skip to content

Conversation

@SchrodingersGat
Copy link
Member

@SchrodingersGat SchrodingersGat commented Jun 16, 2022

Ensure data loaded via the API is sanitized before displaying in EasyMDE

Provides front-end sanitization in parallel with the fixes in #3204

@SchrodingersGat SchrodingersGat added the security Relates to a security issue label Jun 16, 2022
@SchrodingersGat SchrodingersGat requested a review from matmair June 16, 2022 00:02
@matmair
Copy link
Contributor

matmair commented Jun 16, 2022

@SchrodingersGat does this still enable links and styling linke bold, italic etc?

@SchrodingersGat
Copy link
Member Author

Yes, but using markdown - it does not support direct input of HTML

@SchrodingersGat SchrodingersGat merged commit 9bd62f9 into inventree:master Jun 16, 2022
@SchrodingersGat SchrodingersGat deleted the iframe-rejection branch June 16, 2022 00:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Relates to a security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants