mirror of
https://github.com/hedgedoc/hedgedoc.git
synced 2025-05-14 23:24:46 -04:00
Prevent XSS in markdown rendering
This commit is contained in:
parent
fdb9c47354
commit
6700f033ab
5 changed files with 11 additions and 4 deletions
|
@ -2131,6 +2131,7 @@ var lastResult = null;
|
|||
function updateViewInner() {
|
||||
if (currentMode == modeType.edit || !isDirty) return;
|
||||
var value = editor.getValue();
|
||||
value = filterXSS(value); // prevent xss
|
||||
md.meta = {};
|
||||
md.render(value); //only for get meta
|
||||
parseMeta(md, ui.area.markdown, $('#toc'), $('#toc-affix'));
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue