mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-10-26 16:46:12 +01:00
fix: #12887, strip target attribute from remote posts' html
This commit is contained in:
@@ -29,6 +29,9 @@ const sanitizeConfig = {
|
||||
allowedClasses: {
|
||||
'*': [],
|
||||
},
|
||||
allowedAttributes: {
|
||||
a: ['href', 'rel'],
|
||||
},
|
||||
};
|
||||
|
||||
Mocks.profile = async (actors, hostMap) => {
|
||||
|
||||
Reference in New Issue
Block a user