This repository was archived by the owner on Sep 30, 2024. It is now read-only.
Disable injectHTML by default#51400
Merged
Merged
Conversation
eseliger
approved these changes
May 3, 2023
eseliger
left a comment
Member
There was a problem hiding this comment.
We should add some documentation on this and also a changelog entry.
ab5e018 to
5405540
Compare
Contributor
Author
@eseliger I've added it to CHANGELOG and the description in the schema. Is this sufficient? |
eseliger
approved these changes
May 3, 2023
eseliger
left a comment
Member
There was a problem hiding this comment.
Do we use this on one of our continuously deployed environments? If so, we might want to turn on that env var before merging.
indradhanush
approved these changes
May 3, 2023
19a6cb8 to
5fc692a
Compare
Contributor
Author
Just checked on 3 of the instances, none of them are using the feature! |
sashaostrikov
approved these changes
May 3, 2023
doragrgic
approved these changes
May 3, 2023
unknwon
approved these changes
May 3, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change will, by default, disable the HTML injection feature in site-admin. Customers who want to customize their instance can add the environment variable to add scripts or other HTML content. This will make customers (the majority) who don't want this customization feature protected against potential XSS attack.
Test plan
Tested the changes on my local instance.