mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-10-26 16:46:12 +01:00
fix: #12887, strip target attribute from remote posts' html
This commit is contained in:
@@ -29,6 +29,9 @@ const sanitizeConfig = {
|
|||||||
allowedClasses: {
|
allowedClasses: {
|
||||||
'*': [],
|
'*': [],
|
||||||
},
|
},
|
||||||
|
allowedAttributes: {
|
||||||
|
a: ['href', 'rel'],
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
Mocks.profile = async (actors, hostMap) => {
|
Mocks.profile = async (actors, hostMap) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user