Skip to content

Disallow iframe srcdoc for now#7494

Merged
Alkarex merged 1 commit intoFreshRSS:edgefrom
Alkarex:strip-srcdoc
Apr 5, 2025
Merged

Disallow iframe srcdoc for now#7494
Alkarex merged 1 commit intoFreshRSS:edgefrom
Alkarex:strip-srcdoc

Conversation

@Alkarex
Copy link
Member

@Alkarex Alkarex commented Apr 5, 2025

We do not sanitize this attribute well enough, so striped for now.
It is rarely used: I have not seen any use of it in any of my many test feeds.
Can be added back when we can handle its inherent security issues better.

We do not sanitize this attribute well enough, so striped for now.
It is rarely used: I have not seen any use of it in any of my many test feeds.
Can be added back when we can handle its inherent security issues better.
@Alkarex Alkarex added this to the 1.26.2 milestone Apr 5, 2025
@Alkarex Alkarex merged commit 54e2f91 into FreshRSS:edge Apr 5, 2025
1 check passed
@Alkarex Alkarex deleted the strip-srcdoc branch April 5, 2025 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants