]> git.wh0rd.org Git - tt-rss.git/commit
Merge branch 'patch-strip-harmful-tags' into 'master'
authorAndrew Dolgov <cthulhoo@gmail.com>
Sun, 7 Aug 2016 19:21:45 +0000 (22:21 +0300)
committerAndrew Dolgov <cthulhoo@gmail.com>
Sun, 7 Aug 2016 19:21:45 +0000 (22:21 +0300)
commit3b4d9619e90659c16225595a4bbe9b1e6610eb43
tree7fad819ac042937d5ce97880db69199b7fdb14f5
parent48007463861d8db8b2b79c2f4f54e0564edb0ec0
parentd8b0f06705812ef9e4ee4b1943f53dd82743db19
Merge branch 'patch-strip-harmful-tags' into 'master'

Remove href attribute if it executes JavaScript.

Security update to prevent A tags with a `javascript:` href from actually executing the JavaScript.

See merge request !31