commit: 945ce9910dc7b29147ec49af0bdb82202008c7c4
parent: bcae57afd2f932db4b3c4ee28428ed101f0fec1f
Author: kaniini <nenolod@gmail.com>
Date: Tue, 23 Oct 2018 00:56:09 +0000
Merge branch 'bugfix/html-scrub-comments' into 'develop'
html: ensure comments are correctly scrubbed
See merge request pleroma/pleroma!384
Diffstat:
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/lib/pleroma/html.ex b/lib/pleroma/html.ex
@@ -43,8 +43,6 @@ defmodule Pleroma.HTML.Scrubber.TwitterText do
require HtmlSanitizeEx.Scrubber.Meta
alias HtmlSanitizeEx.Scrubber.Meta
- alias Pleroma.HTML
-
Meta.remove_cdata_sections_before_scrub()
Meta.strip_comments()
@@ -83,8 +81,6 @@ defmodule Pleroma.HTML.Scrubber.Default do
require HtmlSanitizeEx.Scrubber.Meta
alias HtmlSanitizeEx.Scrubber.Meta
- alias Pleroma.HTML
-
@markup Application.get_env(:pleroma, :markup)
@uri_schemes Application.get_env(:pleroma, :uri_schemes, [])
@valid_schemes Keyword.get(@uri_schemes, :valid_schemes, [])
@@ -181,6 +177,8 @@ defmodule Pleroma.HTML.Transform.MediaProxy do
{"img", attributes, children}
end
+ def scrub({:comment, children}), do: ""
+
def scrub({tag, attributes, children}), do: {tag, attributes, children}
def scrub({tag, children}), do: children
def scrub(text), do: text