Improved sanitization of href's in editor
This commit is contained in:
@@ -4,6 +4,7 @@ import { NodeSpec, NodeType, Node as ProsemirrorNode } from "prosemirror-model";
|
||||
import * as React from "react";
|
||||
import { Trans } from "react-i18next";
|
||||
import { bytesToHumanReadable } from "../../utils/files";
|
||||
import { sanitizeHref } from "../../utils/urls";
|
||||
import toggleWrap from "../commands/toggleWrap";
|
||||
import FileExtension from "../components/FileExtension";
|
||||
import Widget from "../components/Widget";
|
||||
@@ -56,7 +57,7 @@ export default class Attachment extends Node {
|
||||
{
|
||||
class: `attachment`,
|
||||
id: node.attrs.id,
|
||||
href: node.attrs.href,
|
||||
href: sanitizeHref(node.attrs.href),
|
||||
download: node.attrs.title,
|
||||
"data-size": node.attrs.size,
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user