diff --git a/app/helpers/format_helper.rb b/app/helpers/format_helper.rb index f4110755..67f53b2c 100644 --- a/app/helpers/format_helper.rb +++ b/app/helpers/format_helper.rb @@ -195,10 +195,11 @@ module FormatHelper space_after_headers: true, no_intra_emphasis: true, fenced_code_blocks: true, - disable_indented_code_blocks: true + disable_indented_code_blocks: true, + safe_links_only: true } markdown = Redcarpet::Markdown.new(Redcarpet::Render::HTML.new(escape_html: escape_html), options) - markdown.render(text).html_safe + sanitize(markdown.render(text)) end def markdown_hint(text='') diff --git a/spec/helpers/format_helper_spec.rb b/spec/helpers/format_helper_spec.rb index 11c241bc..dc364c2c 100644 --- a/spec/helpers/format_helper_spec.rb +++ b/spec/helpers/format_helper_spec.rb @@ -11,7 +11,7 @@ describe FormatHelper, type: :helper do it 'should return HTML for header markdown' do expect(Redcarpet::Markdown).to receive(:new) - .with(Redcarpet::Render::HTML, autolink: true, space_after_headers: true, no_intra_emphasis: true, fenced_code_blocks: true, disable_indented_code_blocks: true) + .with(Redcarpet::Render::HTML, autolink: true, space_after_headers: true, no_intra_emphasis: true, fenced_code_blocks: true, disable_indented_code_blocks: true, safe_links_only: true) .and_call_original expect(markdown('# this is my header')).to eq "

this is my header

\n"