mirror of
https://github.com/BoostIo/Boostnote
synced 2025-12-14 10:16:26 +00:00
fix XSS bug
This commit is contained in:
@@ -120,7 +120,7 @@ module.exports = function (md, renderers, defaultRenderer) {
|
|||||||
alt: ['paragraph', 'reference', 'blockquote', 'list']
|
alt: ['paragraph', 'reference', 'blockquote', 'list']
|
||||||
})
|
})
|
||||||
|
|
||||||
for (let name in renderers) {
|
for (const name in renderers) {
|
||||||
md.renderer.rules[`${name}_fence`] = (tokens, index) => renderers[name](tokens[index])
|
md.renderer.rules[`${name}_fence`] = (tokens, index) => renderers[name](tokens[index])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ module.exports = function sanitizePlugin (md, options) {
|
|||||||
options
|
options
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
if (state.tokens[tokenIdx].type === 'fence') {
|
if (state.tokens[tokenIdx].type === '_fence') {
|
||||||
// escapeHtmlCharacters has better performance
|
// escapeHtmlCharacters has better performance
|
||||||
state.tokens[tokenIdx].content = escapeHtmlCharacters(
|
state.tokens[tokenIdx].content = escapeHtmlCharacters(
|
||||||
state.tokens[tokenIdx].content,
|
state.tokens[tokenIdx].content,
|
||||||
|
|||||||
Reference in New Issue
Block a user