gitlab-org--gitlab-foss/spec/lib/banzai
Douwe Maan a14ee68fe4
Merge branch 'markdown-xss-fix-option-2.1' into 'security'
Fix for HackerOne XSS vulnerability in markdown

This is an updated blacklist patch to fix https://dev.gitlab.org/gitlab/gitlabhq/merge_requests/2007. No text is removed. Dangerous schemes/protocols and invalid URIs are left intact but not linked.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/23153

See merge request !2015

Signed-off-by: Rémy Coutable <remy@rymai.me>
2016-11-09 12:26:44 +01:00
..
filter Merge branch 'markdown-xss-fix-option-2.1' into 'security' 2016-11-09 12:26:44 +01:00
pipeline
reference_parser
cross_project_reference_spec.rb
filter_array_spec.rb
note_renderer_spec.rb
object_renderer_spec.rb
querying_spec.rb
redactor_spec.rb
renderer_spec.rb