mirror of
https://github.com/discourse/discourse.git
synced 2025-06-05 09:54:46 +08:00
FIX: Allow sanitized-HTML in GH issues and categories oneboxes. (#25374)
Follow-up to d78357917c
Related meta topic: https://meta.discourse.org/t/html-is-not-render-on-category-onebox-description/289424:
This commit is contained in:
@ -16,7 +16,7 @@ RSpec.describe Onebox::Engine::GithubIssueOnebox do
|
||||
describe "#to_html" do
|
||||
it "sanitizes the input and transform the emoji into an img tag" do
|
||||
sanitized_label =
|
||||
'Test <img src="/images/emoji/twitter/+1.png?v=12" title="+1" class="emoji" alt="+1" loading="lazy" width="20" height="20"> <style>body {display: none}</style>'
|
||||
'Test <img src="/images/emoji/twitter/+1.png?v=12" title="+1" class="emoji" alt="+1" loading="lazy" width="20" height="20">'
|
||||
|
||||
expect(html).to include(sanitized_label)
|
||||
end
|
||||
|
Reference in New Issue
Block a user