[v10.0.x] Chore: remove pre tags from DOMPurify config (#68593)

Chore: remove pre tags from DOMPurify config (#68512)

(cherry picked from commit 4ccaf801d7)

Co-authored-by: Kristian Bremberg <114284895+KristianGrafana@users.noreply.github.com>
This commit is contained in:
Grot (@grafanabot)
2023-05-16 22:22:41 +00:00
committed by GitHub
co-authored by Kristian Bremberg
parent 4dc76672d3
commit 714f9b5e7a
+2 -2
View File
@@ -33,13 +33,13 @@ const sanitizeTextPanelWhitelist = new xss.FilterXSS({
/** /**
* Return a sanitized string that is going to be rendered in the browser to prevent XSS attacks. * Return a sanitized string that is going to be rendered in the browser to prevent XSS attacks.
* Note that sanitized tags will be removed, such as "<script>". * Note that sanitized tags will be removed, such as "<script>".
* We don't allow form, pre, or input elements. * We don't allow form or input elements.
*/ */
export function sanitize(unsanitizedString: string): string { export function sanitize(unsanitizedString: string): string {
try { try {
return DOMPurify.sanitize(unsanitizedString, { return DOMPurify.sanitize(unsanitizedString, {
USE_PROFILES: { html: true }, USE_PROFILES: { html: true },
FORBID_TAGS: ['form', 'input', 'pre'], FORBID_TAGS: ['form', 'input'],
}); });
} catch (error) { } catch (error) {
console.error('String could not be sanitized', unsanitizedString); console.error('String could not be sanitized', unsanitizedString);