]> source.dussan.org Git - gitea.git/commit
Use restricted sanitizer for repository description (#28141)
authorEarl Warren <109468362+earl-warren@users.noreply.github.com>
Thu, 23 Nov 2023 16:34:25 +0000 (17:34 +0100)
committerGitHub <noreply@github.com>
Thu, 23 Nov 2023 16:34:25 +0000 (16:34 +0000)
commit1075ff74b5050f671c5f9824ae39390230b3c85d
tree341f0d13f5f804ed81f00cb8f3b023bab1eeb0dd
parent7d1933717d5eff2011128084693d57308d8102a4
Use restricted sanitizer for repository description (#28141)

- Currently the repository description uses the same sanitizer as a
normal markdown document. This means that element such as heading and
images are allowed and can be abused.
- Create a minimal restricted sanitizer for the repository description,
which only allows what the postprocessor currently allows, which are
links and emojis.
- Added unit testing.
- Resolves https://codeberg.org/forgejo/forgejo/issues/1202
- Resolves https://codeberg.org/Codeberg/Community/issues/1122

(cherry picked from commit 631c87cc2347f0036a75dcd21e24429bbca28207)

Co-authored-by: Gusted <postmaster@gusted.xyz>
models/repo/repo.go
modules/markup/sanitizer.go
modules/markup/sanitizer_test.go