mirror of
https://github.com/FreshRSS/FreshRSS.git
synced 2026-05-19 22:04:50 -04:00
SimplePie forbit formaction attribute (#7506)
Sanitize buttons with a form or formaction attribute.
This commit is contained in:
committed by
GitHub
parent
be73c6d669
commit
f58dea6a5a
@@ -348,7 +348,8 @@ function customSimplePie(array $attributes = [], array $curl_options = []): \Sim
|
||||
]);
|
||||
$simplePie->rename_attributes(['id', 'class']);
|
||||
$simplePie->strip_attributes(array_merge($simplePie->strip_attributes, [
|
||||
'autoplay', 'class', 'onload', 'onunload', 'onclick', 'ondblclick', 'onmousedown', 'onmouseup',
|
||||
'autoplay', 'class', 'form', 'formaction',
|
||||
'onload', 'onunload', 'onclick', 'ondblclick', 'onmousedown', 'onmouseup',
|
||||
'onmouseover', 'onmousemove', 'onmouseout', 'onfocus', 'onblur',
|
||||
'onkeypress', 'onkeydown', 'onkeyup', 'onselect', 'onchange', 'seamless', 'sizes', 'srcdoc', 'srcset']));
|
||||
$simplePie->add_attributes([
|
||||
|
||||
Reference in New Issue
Block a user