Comments (7)
What maps?
What HTML tags?
What various places?
from wekan.
If this is about any new security issue, please follow security disclosure:
https://github.com/wekan/wekan/blob/main/SECURITY.md
from wekan.
But not escaping something is OK, when it does not create any kind of alert javascript popup like in XSS, because WeKan uses dompurify:
https://wekan.github.io/hall-of-fame/
from wekan.
It is a feature in WeKan, that is is possible to use some markdown and html for formatting.
from wekan.
@xet7
I would like to briefly explain the problem that I discovered today in more detail: We use a board to implement XML export files. For this purpose we also create cards where we mention XML tags.
We noticed the problem when we wrote the following for the title of a card: "The XML tag <person> needs to be changed to <pers>"
After saving the map or title, it only said "The XML tag needs to be changed to".
If html-tags are a feature for formating, is it possible to disable it for all boards or for one board?
from wekan.
Pull requests welcome.
https://github.com/wekan/wekan/blob/main/packages/markdown/src/template-integration.js#L76
Building WeKan and sending pull request:
http://github.com/wekan/wekan/wiki/Emoji
from wekan.
@xet7
Thank you for the information, but I'm not familiar with Node.js so I can't create a pull request. Maybe someone is also interessted in this feature. And we know it for the future to do not write something with < and >
from wekan.
Related Issues (20)
- Images Upload issue HOT 4
- Sandstorm Marketplace Version Significantly Outdated HOT 5
- feature request: As user I want to store and follow URL, maybe with a new custom field type "URL" HOT 4
- Old wekan version in snapstore HOT 9
- Problem with language in Wekan Docker Containter HOT 4
- Markdown and copy buttons on top of text
- OIDC sign in button does nothing iOS Brave/FF Focus - pop-up vs redirection implementation HOT 1
- illegal unescaped char: ( when signing in with LDAP_SYNC_ADMIN_STATUS: 'true' and "()" character in cn HOT 2
- Wekan Snap cannot override files HOT 1
- [Bug] Json import do not import all the cards HOT 2
- Add missing Webhook data information for "act-editComment" HOT 1
- Azure AD B2C HOT 9
- OIDC with Zitadel not working HOT 6
- get last change date of a list using API HOT 1
- Metrics - docker-compose.yml error variable name HOT 2
- Wekan 7.27 - Metrics error: TypeError: Cannot read property 'title' of undefined HOT 2
- Raspberry pi docker error with '[FilesCollection.attachments] Path "/data/attachments" is not writable!', HOT 1
- the board I left before still exist in database HOT 15
- Error: Cannot find module '../' (fibers) HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from wekan.