yogthos/markdown-clj

Prevent potential XSS by default

開放

#188 建立於 2022年10月12日

 (1 則留言) (0 個反應) (0 位負責人)Clojure (120 個分叉)github user discovery
bughelp wanted

倉庫指標

星標
 (570 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Example markdown:

[click me](javascript:window.onerror=alert;throw%20document.URL)

Markdown clj will render:

Maybe we force folks to specify specific protocols they want to support and validate the urls? We just discovered this and haven't done much analysis at this point.

This is what other popular Java markdown tools do:

https://github.com/commonmark/commonmark-java/blob/main/commonmark/src/main/java/org/commonmark/renderer/html/DefaultUrlSanitizer.java

Note, this doesn't affect other online editors either:

https://dillinger.io/ https://stackedit.io/app# https://jbt.github.io/markdown-editor/

貢獻者指南