Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pref: editor iframe risk with src tag #6150

Merged
merged 3 commits into from
Jun 26, 2024

Conversation

LIlGG
Copy link
Member

@LIlGG LIlGG commented Jun 26, 2024

What type of PR is this?

/kind improvement
/area editor
/milestone 2.17.x

What this PR does / why we need it:

在用户设置 iframe 相关的 src 时,检测设置的链接是否符合白名单。如果不符合则不允许设置。

see ueberdosis/tiptap#5160

How to test it?

测试在 iframe 中的 src 输入 javascript: alert("1") 时是否会触发 javascript

Does this PR introduce a user-facing change?

处理默认编辑器中 iframe 标签的 src 属性可能存在的风险

@f2c-ci-robot f2c-ci-robot bot added kind/improvement Categorizes issue or PR as related to a improvement. release-note Denotes a PR that will be considered when it comes time to generate release notes. labels Jun 26, 2024
@f2c-ci-robot f2c-ci-robot bot added this to the 2.17.x milestone Jun 26, 2024
@f2c-ci-robot f2c-ci-robot bot added the area/editor Issues or PRs related to the Editor label Jun 26, 2024
@f2c-ci-robot f2c-ci-robot bot requested review from QuentinHsu and wzrove June 26, 2024 09:56
Copy link
Member

@ruibaby ruibaby left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@f2c-ci-robot f2c-ci-robot bot added the lgtm Indicates that a PR is ready to be merged. label Jun 26, 2024
Copy link

codecov bot commented Jun 26, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 55.08%. Comparing base (5fdf6c0) to head (9bbf701).
Report is 271 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main    #6150      +/-   ##
============================================
- Coverage     56.91%   55.08%   -1.83%     
- Complexity     3319     3490     +171     
============================================
  Files           587      635      +48     
  Lines         18968    21388    +2420     
  Branches       1401     1496      +95     
============================================
+ Hits          10795    11781     +986     
- Misses         7594     9002    +1408     
- Partials        579      605      +26     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@f2c-ci-robot f2c-ci-robot bot removed the lgtm Indicates that a PR is ready to be merged. label Jun 26, 2024
Signed-off-by: Ryan Wang <[email protected]>
Copy link
Member

@guqing guqing left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@f2c-ci-robot f2c-ci-robot bot added the lgtm Indicates that a PR is ready to be merged. label Jun 26, 2024
Copy link
Member

@JohnNiang JohnNiang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

Copy link

f2c-ci-robot bot commented Jun 26, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: JohnNiang

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@f2c-ci-robot f2c-ci-robot bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 26, 2024
@f2c-ci-robot f2c-ci-robot bot merged commit 5aacd8a into halo-dev:main Jun 26, 2024
7 checks passed
@ruibaby ruibaby modified the milestones: 2.17.x, 2.17.0 Jun 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. area/editor Issues or PRs related to the Editor kind/improvement Categorizes issue or PR as related to a improvement. lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants