Merge pull request #2894 from hennevogel/security/2892

Sanitize rendered markdown
This commit is contained in:
Henne Vogelsang 2021-10-11 18:22:14 +02:00 committed by GitHub
commit ff0bdf2462
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 4 additions and 3 deletions

View file

@ -195,10 +195,11 @@ module FormatHelper
space_after_headers: true,
no_intra_emphasis: true,
fenced_code_blocks: true,
disable_indented_code_blocks: true
disable_indented_code_blocks: true,
safe_links_only: true
}
markdown = Redcarpet::Markdown.new(Redcarpet::Render::HTML.new(escape_html: escape_html), options)
markdown.render(text).html_safe
sanitize(markdown.render(text))
end
def markdown_hint(text='')

View file

@ -11,7 +11,7 @@ describe FormatHelper, type: :helper do
it 'should return HTML for header markdown' do
expect(Redcarpet::Markdown).to receive(:new)
.with(Redcarpet::Render::HTML, autolink: true, space_after_headers: true, no_intra_emphasis: true, fenced_code_blocks: true, disable_indented_code_blocks: true)
.with(Redcarpet::Render::HTML, autolink: true, space_after_headers: true, no_intra_emphasis: true, fenced_code_blocks: true, disable_indented_code_blocks: true, safe_links_only: true)
.and_call_original
expect(markdown('# this is my header')).to eq "<h1>this is my header</h1>\n"