#1932 disallow css urls
This commit is contained in:
@@ -322,7 +322,9 @@ class DText
|
||||
"href" => ["http", "https", :relative]
|
||||
}
|
||||
},
|
||||
:css => Sanitize::Config::RELAXED[:css]
|
||||
:css => Sanitize::Config::RELAXED[:css].merge({
|
||||
:protocols => []
|
||||
})
|
||||
)
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user