You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In our preview generator for CommonMark Markdown files, we allow clickable links, including hash: links. That means we don't use cmark's "safe" link checker that prohibits javascript: links, among other protocols.
We should probably maintain our own whitelist.
http
hash
data?
ftp
NOT file
mailto
Let's look at cmark to see what else.
The text was updated successfully, but these errors were encountered:
In our preview generator for CommonMark Markdown files, we allow clickable links, including
hash:
links. That means we don't use cmark's "safe" link checker that prohibitsjavascript:
links, among other protocols.We should probably maintain our own whitelist.
Let's look at cmark to see what else.
The text was updated successfully, but these errors were encountered: