matrix-org/synapse

Upgrade to Bleach 1.5, to limit link schemes to an allowlist

Open

#2,860 建立於 2018年2月9日

在 GitHub 查看
 (3 留言) (0 反應) (0 負責人)Python (11,713 star) (2,196 fork)batch import
A-Email-PushP4T-EnhancementZ-Help-Wantedgood first issue

描述

The 1.5 version of Bleach made the allowed protocols configurable: http://bleach.readthedocs.io/en/latest/clean.html#allowed-protocols-protocols

Once the dependency is updated, the safe_markup function in the mailer can be updated and these lines can be uncommented: https://github.com/matrix-org/synapse/blob/42b50483be2b022735f8ae2107314d51e92e8471/synapse/push/mailer.py#L76-L77

貢獻者指南

Upgrade to Bleach 1.5, to limit link schemes to an allowlist · matrix-org/synapse#2860 | Good First Issue