yogthos/markdown-clj

Prevent potential XSS by default

Ouverte

#188 ouverte le 12 oct. 2022

 (1 commentaire) (0 réaction) (0 personne assignée)Clojure (120 forks)github user discovery
bughelp wanted

Métriques du dépôt

Stars
 (570 étoiles)
Métriques de merge PR
 (Métriques PR en attente)

Description

Example markdown:

[click me](javascript:window.onerror=alert;throw%20document.URL)

Markdown clj will render:

Maybe we force folks to specify specific protocols they want to support and validate the urls? We just discovered this and haven't done much analysis at this point.

This is what other popular Java markdown tools do:

https://github.com/commonmark/commonmark-java/blob/main/commonmark/src/main/java/org/commonmark/renderer/html/DefaultUrlSanitizer.java

Note, this doesn't affect other online editors either:

https://dillinger.io/ https://stackedit.io/app# https://jbt.github.io/markdown-editor/

Guide contributeur