0652471164
This is an XSS vulnribilitiy. This also blocks a number of MD attributes that a user might attempt to use. The following are the allowed attributes. ['a', 'abbr', 'acronym', 'b', 'blockquote', 'code', 'em', 'i', 'li', 'ol', 'p', 'pre', 'strong', 'ul'] I belive this to be acceptable, as honeslty, a speaker using H1 is going to stomp all over the page and make it harder for the reviewer to parse. UX wise, it's less than great. A user can do # title and be left with <h1> in the sanitized output. |
||
---|---|---|
.. | ||
conference | ||
locale | ||
proposals | ||
reviews | ||
schedule | ||
speakers | ||
sponsorship | ||
static | ||
teams | ||
utils | ||
__init__.py | ||
conf.py | ||
markdown_parser.py | ||
models.py | ||
views.py |