[v10.0.x] Chore: remove pre tags from DOMPurify config (#68593)
Chore: remove pre tags from DOMPurify config (#68512)
(cherry picked from commit 4ccaf801d7)
Co-authored-by: Kristian Bremberg <114284895+KristianGrafana@users.noreply.github.com>
This commit is contained in:
co-authored by
Kristian Bremberg
parent
4dc76672d3
commit
714f9b5e7a
@@ -33,13 +33,13 @@ const sanitizeTextPanelWhitelist = new xss.FilterXSS({
|
|||||||
/**
|
/**
|
||||||
* Return a sanitized string that is going to be rendered in the browser to prevent XSS attacks.
|
* Return a sanitized string that is going to be rendered in the browser to prevent XSS attacks.
|
||||||
* Note that sanitized tags will be removed, such as "<script>".
|
* Note that sanitized tags will be removed, such as "<script>".
|
||||||
* We don't allow form, pre, or input elements.
|
* We don't allow form or input elements.
|
||||||
*/
|
*/
|
||||||
export function sanitize(unsanitizedString: string): string {
|
export function sanitize(unsanitizedString: string): string {
|
||||||
try {
|
try {
|
||||||
return DOMPurify.sanitize(unsanitizedString, {
|
return DOMPurify.sanitize(unsanitizedString, {
|
||||||
USE_PROFILES: { html: true },
|
USE_PROFILES: { html: true },
|
||||||
FORBID_TAGS: ['form', 'input', 'pre'],
|
FORBID_TAGS: ['form', 'input'],
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
console.error('String could not be sanitized', unsanitizedString);
|
console.error('String could not be sanitized', unsanitizedString);
|
||||||
|
|||||||
Reference in New Issue
Block a user