Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensure arbitary JS and HTML is not rendered on EventViewPage #264

Open
kylecombes opened this issue Oct 28, 2020 · 0 comments
Open

Ensure arbitary JS and HTML is not rendered on EventViewPage #264

kylecombes opened this issue Oct 28, 2020 · 0 comments
Labels

Comments

@kylecombes
Copy link
Collaborator

I'm not sure if this is a problem or not, but it just occurred to me when thinking of Markdown in another context: If the user enters HTML or JavaScript, does it get rendered by the Markdown renderer? We don't want the user to be able to inject JS into the page (huge security hole), and we probably want to restrict the kinds of HTML people can use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant