You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
forgejo/modules/markup
KN4CK3R 8af96f585f
Disallow dangerous url schemes (#25960)
Regression: https://github.com/go-gitea/gitea/pull/24805
Closes: #25945

- Disallow `javascript`, `vbscript` and `data` (data uri images still
work) url schemes even if all other schemes are allowed
- Fixed older `cbthunderlink` tests

---------

Co-authored-by: delvh <dev.lh@web.de>
12 months ago
..
asciicast Support asciicast files as new markup (#22448) 1 year ago
common Implement FSFE REUSE for golang files (#21840) 2 years ago
console Add context when rendering labels or emojis (#23281) 1 year ago
csv Add context when rendering labels or emojis (#23281) 1 year ago
external Log STDERR of external renderer when it fails (#22442) 1 year ago
markdown Replace `interface{}` with `any` (#25686) 1 year ago
mdstripper Implement FSFE REUSE for golang files (#21840) 2 years ago
orgmode Upgrade go dependencies (#25819) 12 months ago
camo.go Implement FSFE REUSE for golang files (#21840) 2 years ago
camo_test.go Implement FSFE REUSE for golang files (#21840) 2 years ago
html.go Add RTL rendering support to Markdown (#24816) 1 year ago
html_internal_test.go Replace `interface{}` with `any` (#25686) 1 year ago
html_test.go Refactor path & config system (#25330) 1 year ago
renderer.go Add RTL rendering support to Markdown (#24816) 1 year ago
renderer_test.go Move `IsReadmeFile*` from `modules/markup/` to `modules/util` (#22877) 1 year ago
sanitizer.go Disallow dangerous url schemes (#25960) 12 months ago
sanitizer_test.go Disallow dangerous url schemes (#25960) 12 months ago