Skip to content

Commit

Permalink
fix(designer-ui): Partial port of #4554 - Add raw HTML sanitization
Browse files Browse the repository at this point in the history
  • Loading branch information
ek68794998 committed Apr 6, 2024
1 parent b97983d commit 4645ebb
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion libs/designer-ui/src/lib/html/plugins/toolbar/helper/util.ts
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,8 @@ export const encodeOrDecodeSegmentValue = (value: string, encodingMap: Record<st
};

export const getDomFromHtmlEditorString = (htmlEditorString: string, nodeMap: Map<string, ValueSegment>): HTMLElement => {
const encodedHtmlEditorString = encodeStringSegmentTokensInDomContext(htmlEditorString, nodeMap);
const purifiedHtmlEditorString = htmlEditorString.replace(/on[a-z]*\s*=\s*('[^']+|"[^"]+|[^\s>]+)/gi, '');
const encodedHtmlEditorString = encodeStringSegmentTokensInDomContext(purifiedHtmlEditorString, nodeMap);

const tempElement = document.createElement('div');
tempElement.innerHTML = encodedHtmlEditorString;
Expand Down

0 comments on commit 4645ebb

Please sign in to comment.