0
0
Fork 0
mirror of https://github.com/go-gitea/gitea synced 2024-12-23 05:34:50 +01:00
gitea/models
Earl Warren 1075ff74b5
Use restricted sanitizer for repository description (#28141)
- Currently the repository description uses the same sanitizer as a
normal markdown document. This means that element such as heading and
images are allowed and can be abused.
- Create a minimal restricted sanitizer for the repository description,
which only allows what the postprocessor currently allows, which are
links and emojis.
- Added unit testing.
- Resolves https://codeberg.org/forgejo/forgejo/issues/1202
- Resolves https://codeberg.org/Codeberg/Community/issues/1122

(cherry picked from commit 631c87cc2347f0036a75dcd21e24429bbca28207)

Co-authored-by: Gusted <postmaster@gusted.xyz>
2023-11-23 16:34:25 +00:00
..
actions Fix no ActionTaskOutput table waring (#28149) 2023-11-21 08:02:51 +00:00
activities Refactor Find Sources and fix bug when view a user who belongs to an unactive auth source (#27798) 2023-11-03 01:41:00 +00:00
admin
asymkey Replace more db.DefaultContext (#27628) 2023-10-15 17:46:06 +02:00
auth Fix wrong xorm Delete usage (#27995) 2023-11-12 07:38:45 +00:00
avatars Final round of db.DefaultContext refactor (#27587) 2023-10-14 08:37:24 +00:00
db refactor: make db iterate context aware (#27710) 2023-10-21 10:05:29 +08:00
dbfs
fixtures Add unit tests for action runner token (#27670) 2023-10-19 07:24:24 +00:00
git Upgrade xorm to 1.3.4 (#27807) 2023-10-27 13:28:53 +02:00
issues Enable system users for comment.LoadPoster (#28014) 2023-11-13 15:30:08 +01:00
migrations Add Index to pull_auto_merge.doer_id (#27811) 2023-10-30 08:39:29 +00:00
organization
packages Revert "packages: Calculate package size quota using package creator ID instead of owner ID (#28007)" (#28049) 2023-11-14 16:03:56 +01:00
perm
project
pull Add Index to pull_auto_merge.doer_id (#27811) 2023-10-30 08:39:29 +00:00
repo Use restricted sanitizer for repository description (#28141) 2023-11-23 16:34:25 +00:00
secret
shared/types
system Fix system config cache expiration timing (#28072) 2023-11-16 12:53:42 +00:00
unit
unittest Upgrade xorm (#27673) 2023-10-19 10:25:57 +00:00
user Replace -1 with GhostUserID (#27703) 2023-10-20 14:43:08 +00:00
webhook Final round of db.DefaultContext refactor (#27587) 2023-10-14 08:37:24 +00:00
error.go
fixture_generation.go Replace more db.DefaultContext (#27628) 2023-10-15 17:46:06 +02:00
fixture_test.go Replace more db.DefaultContext (#27628) 2023-10-15 17:46:06 +02:00
main_test.go
org.go Refactor the function RemoveOrgUser (#27582) 2023-11-03 14:01:45 +00:00
org_team.go Refactor the function RemoveOrgUser (#27582) 2023-11-03 14:01:45 +00:00
org_team_test.go
org_test.go Replace more db.DefaultContext (#27628) 2023-10-15 17:46:06 +02:00
repo.go
repo_test.go
repo_transfer.go
repo_transfer_test.go