mirror of
https://github.com/discourse/discourse.git
synced 2024-11-23 14:49:07 +08:00
FIX: better whitelisting
This commit is contained in:
parent
9828a268b9
commit
d54c28adc1
|
@ -258,6 +258,6 @@ Discourse.Markdown.whiteListTag('span', 'bbcode-i');
|
|||
Discourse.Markdown.whiteListTag('span', 'bbcode-u');
|
||||
Discourse.Markdown.whiteListTag('span', 'bbcode-s');
|
||||
|
||||
Discourse.Markdown.whiteListTag('span', 'class', /bbcode-size-\d+$/);
|
||||
Discourse.Markdown.whiteListTag('span', 'class', /^bbcode-size-\d+$/);
|
||||
|
||||
Discourse.Markdown.whiteListIframe(/^(https?:)?\/\/www\.google\.com\/maps\/embed\?.+/i);
|
||||
|
|
|
@ -244,6 +244,8 @@ describe PrettyText do
|
|||
|
||||
it "sanitizes spans" do
|
||||
PrettyText.cook("<span class=\"-bbcode-size-0 fa fa-spin\">a</span>").should match_html "<p><span>a</span></p>"
|
||||
PrettyText.cook("<span class=\"fa fa-spin -bbcode-size-0\">a</span>").should match_html "<p><span>a</span></p>"
|
||||
PrettyText.cook("<span class=\"bbcode-size-10\">a</span>").should match_html "<p><span class=\"bbcode-size-10\">a</span></p>"
|
||||
end
|
||||
|
||||
it "bolds stuff in parens" do
|
||||
|
|
Loading…
Reference in New Issue
Block a user