Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for html tags #46

Open
00sapo opened this issue Feb 13, 2019 · 1 comment
Open

Add support for html tags #46

00sapo opened this issue Feb 13, 2019 · 1 comment
Labels

Comments

@00sapo
Copy link

00sapo commented Feb 13, 2019

It would be useful if Shiba could support standard html tags, such as iframes. It would allow to include a lot of contents (e.g. YouTube, etc...)

@rhysd
Copy link
Owner

rhysd commented Feb 25, 2019

I'm sorry for catching this issue late.

Due to security reason, HTML tags are sanitized. Some HTML tags such as <img>, <cite>, <kbd>, ... (listed here). This is the same as GitHub.

https://github.com/rhysd/marked-sanitizer-github

Without this sanitization, loading malicious markdown documentation causes arbitrary code execution (reported at #42).

@rhysd rhysd added the question label Feb 25, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants