This repository has been archived by the owner on Sep 11, 2024. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 832
Allow [bf]g colors for <font> style attrib #610
Merged
Merged
Commits on Jan 11, 2017
-
Allow [bf]g colors for <font> style attrib
Instead of dropping the style attribute on `<font>` tags entirely, sanitise aggressively and only keep `background-color` and `color` keys, and also sanitise the values to prevent `url(XXXXXX)` and `expression(XXXXXX)` type XSS attacks.
Luke Barnard committedJan 11, 2017 Configuration menu - View commit details
-
Copy full SHA for 8e3f2eb - Browse repository at this point
Copy the full SHA 8e3f2ebView commit details -
Luke Barnard committed
Jan 11, 2017 Configuration menu - View commit details
-
Copy full SHA for 32185be - Browse repository at this point
Copy the full SHA 32185beView commit details
Commits on Feb 9, 2017
-
Configuration menu - View commit details
-
Copy full SHA for ae03244 - Browse repository at this point
Copy the full SHA ae03244View commit details
Commits on Feb 27, 2017
-
Sanitise for *, fix style issues
Luke Barnard committedFeb 27, 2017 Configuration menu - View commit details
-
Copy full SHA for 886b0a3 - Browse repository at this point
Copy the full SHA 886b0a3View commit details -
Allow span, and only allow style attrib
Luke Barnard committedFeb 27, 2017 Configuration menu - View commit details
-
Copy full SHA for 5fc828f - Browse repository at this point
Copy the full SHA 5fc828fView commit details
Commits on Mar 2, 2017
-
Use data-mx[-bg]-color instead of stripping style
This has the benefit of not needing a spec for custom CSS. Instead we rigourously sanitise the values for custom data attributes that are transformed to CSS equivalents. `data-mx-color` translates to CSS `color` for example.
Luke Barnard committedMar 2, 2017 Configuration menu - View commit details
-
Copy full SHA for 36795fa - Browse repository at this point
Copy the full SHA 36795faView commit details -
Remove custom attribs as consumed
Luke Barnard committedMar 2, 2017 Configuration menu - View commit details
-
Copy full SHA for b951713 - Browse repository at this point
Copy the full SHA b951713View commit details -
Luke Barnard committed
Mar 2, 2017 Configuration menu - View commit details
-
Copy full SHA for 0f8ab99 - Browse repository at this point
Copy the full SHA 0f8ab99View commit details -
Luke Barnard committed
Mar 2, 2017 Configuration menu - View commit details
-
Copy full SHA for f4278b6 - Browse repository at this point
Copy the full SHA f4278b6View commit details
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.