gitlab-org--gitlab-foss/spec/lib/banzai/filter
Douwe Maan a14ee68fe4
Merge branch 'markdown-xss-fix-option-2.1' into 'security'
Fix for HackerOne XSS vulnerability in markdown

This is an updated blacklist patch to fix https://dev.gitlab.org/gitlab/gitlabhq/merge_requests/2007. No text is removed. Dangerous schemes/protocols and invalid URIs are left intact but not linked.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/23153

See merge request !2015

Signed-off-by: Rémy Coutable <remy@rymai.me>
2016-11-09 12:26:44 +01:00
..
abstract_link_filter_spec.rb
autolink_filter_spec.rb Merge branch 'markdown-xss-fix-option-2.1' into 'security' 2016-11-09 12:26:44 +01:00
blockquote_fence_filter_spec.rb
commit_range_reference_filter_spec.rb
commit_reference_filter_spec.rb
emoji_filter_spec.rb Convert UTF-8 Emoji to Gitlab emoji 2016-10-13 13:18:30 +02:00
external_issue_reference_filter_spec.rb Fix Markdown styling inside reference links 2016-11-01 09:49:30 +00:00
external_link_filter_spec.rb Add Nofollow for uppercased scheme in external url 2016-10-18 13:54:02 +01:00
gollum_tags_filter_spec.rb
html_entity_filter_spec.rb fix: commit messages being double-escaped in activies tab 2016-10-18 05:06:02 -07:00
image_link_filter_spec.rb
inline_diff_filter_spec.rb
issue_reference_filter_spec.rb Fix Markdown styling inside reference links 2016-11-01 09:49:30 +00:00
label_reference_filter_spec.rb Unfold references for group labels when moving issue to another project 2016-10-19 14:58:25 -02:00
merge_request_reference_filter_spec.rb
milestone_reference_filter_spec.rb
redactor_filter_spec.rb Merge branch 'issue_23548_dev' into 'master' 2016-11-09 12:25:17 +01:00
reference_filter_spec.rb
relative_link_filter_spec.rb Add failing test for #21420 2016-10-24 22:18:34 +02:00
sanitization_filter_spec.rb
snippet_reference_filter_spec.rb
syntax_highlight_filter_spec.rb Fixed banzai test failures 2016-10-04 16:13:55 +01:00
table_of_contents_filter_spec.rb
upload_link_filter_spec.rb
user_reference_filter_spec.rb Fix Markdown styling inside reference links 2016-11-01 09:49:30 +00:00
video_link_filter_spec.rb
wiki_link_filter_spec.rb
yaml_front_matter_filter_spec.rb