mirror of
https://github.com/scinote-eln/scinote-web.git
synced 2025-02-28 17:54:16 +08:00
Merge pull request #6315 from okriuchykhin/ok_SCI_9369
Reduce allowed data attributes in sanitizer config only to data-mce-token [SCI-9369]
This commit is contained in:
commit
9745ef62dc
1 changed files with 1 additions and 1 deletions
|
@ -324,7 +324,7 @@ class Constants
|
|||
config = Sanitize::Config::RELAXED.deep_dup
|
||||
config[:attributes][:all] << 'id'
|
||||
config[:attributes][:all] << 'contenteditable'
|
||||
config[:attributes][:all] << :data
|
||||
config[:attributes]['img'] << 'data-mce-token'
|
||||
INPUT_SANITIZE_CONFIG = Sanitize::Config.freeze_config(config)
|
||||
|
||||
REPOSITORY_DEFAULT_PAGE_SIZE = 10
|
||||
|
|
Loading…
Reference in a new issue