David Ormsbee
authored
Sanitizes Markdown that goes back and forth between the server and client side, to strip out data: links, so that they cannot be abused. There is no present vulnerability to this issue–modern browsers disallow data links in the first place, and we already filter this out in both client-side code as well as the HTML generated in the REST API (it's run through bleach). But we're adding this anyway, to further reduce the odds that some client-side mistake could cause a vulnerability. This is part of TNL-8589.
Name | Last commit | Last update |
---|