#1932 disallow css urls
This commit is contained in:
@@ -322,7 +322,9 @@ class DText
|
|||||||
"href" => ["http", "https", :relative]
|
"href" => ["http", "https", :relative]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
:css => Sanitize::Config::RELAXED[:css]
|
:css => Sanitize::Config::RELAXED[:css].merge({
|
||||||
|
:protocols => []
|
||||||
|
})
|
||||||
)
|
)
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
Reference in New Issue
Block a user