提交 535c1115 编写于 作者: V Vojtech Juranek 提交者: Jesse Glick

[FIXED SECURITY-76] Prevent iframe injection, forbid iframe by default

上级 8ac74c35
......@@ -66,7 +66,6 @@ public class MyspacePolicy {
tag("span,div");
tag("img", "src",ONSITE_OR_OFFSITE_URL,
"hspace","vspace");
tag("iframe", "src");
tag("link", "type","rel");
tag("ul,ol,li,dd,dl,dt,thead,tbody,tfoot");
tag("table", "noresize");
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册