mirror of https://github.com/go-gitea/gitea
Disallow dangerous url schemes (#25960)
Regression: https://github.com/go-gitea/gitea/pull/24805 Closes: #25945 - Disallow `javascript`, `vbscript` and `data` (data uri images still work) url schemes even if all other schemes are allowed - Fixed older `cbthunderlink` tests --------- Co-authored-by: delvh <dev.lh@web.de>pull/25907/head^2
parent
cc73e84fa3
commit
8af96f585f
Loading…
Reference in new issue