Releases: flavorjones/loofah
Releases · flavorjones/loofah
2.10.0 / 2021-06-06
2.10.0 / 2021-06-06
Features
- Allow CSS properties
overflow-x
andoverflow-y
. [#206] (Thanks, @sampokuokkanen!)
2.9.1 / 2021-04-07
2.9.1 / 2021-04-07
Bug fixes
- Fix a regression in v2.9.0 which inappropriately removed CSS properties with quoted string values. [#202]
2.9.0 / 2021-01-14
2.8.0 / 2020-11-25
2.8.0 / 2020-11-25
- Allow CSS properties
order
,flex-direction
,flex-grow
,flex-wrap
,flex-shrink
,flex-flow
,flex-basis
,flex
,justify-content
,align-self
,align-items
, andalign-content
. [#197] (Thanks, @miguelperez!)
2.7.0 / 2020-08-26
2.6.0 / 2020-06-16
2.5.0 / 2020-04-05
2.5.0 / 2020-04-05
Features
- Allow more CSS length units: "ch", "vw", "vh", "Q", "lh", "vmin", "vmax". [#178] (Thanks, @JuanitoFatas!)
Fixes
- Remove comments from
Loofah::HTML::Document
s that exist outside thehtml
element. [#80]
Other changes
- Gem metadata being set [#181] (Thanks, @JuanitoFatas!)
- Test files removed from gem file [#180,#166,#159] (Thanks, @JuanitoFatas and @greysteil!)
2.4.0 / 2019-11-25
2.3.1 / 2019-10-22
2.3.1 / 2019-10-22
Security
Address CVE-2019-15587: Unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
This CVE's public notice is at #171
2.3.0 / 2019-09-28
2.3.0 / 2019-09-28
Features
- Expand set of allowed protocols to include
tel:
andline:
. [#104, #147] - Expand set of allowed CSS functions. [related to #122]
- Allow greater precision in shorthand CSS values. [#149] (Thanks, @danfstucky!)
- Allow CSS property
list-style
[#162] (Thanks, @jaredbeck!) - Allow CSS keywords
thick
andthin
[#168] (Thanks, @georgeclaghorn!) - Allow HTML property
contenteditable
[#167] (Thanks, @andreynering!)
Bug fixes
- CSS hex values are no longer limited to lowercase hex. Previously uppercase hex were scrubbed. [#165] (Thanks, @asok!)
Deprecations / Name Changes
The following method and constants are hereby deprecated, and will be completely removed in a future release:
- Deprecate
Loofah::Helpers::ActionView.white_list_sanitizer
, please useLoofah::Helpers::ActionView.safe_list_sanitizer
instead. - Deprecate
Loofah::Helpers::ActionView::WhiteListSanitizer
, please useLoofah::Helpers::ActionView::SafeListSanitizer
instead. - Deprecate
Loofah::HTML5::WhiteList
, please useLoofah::HTML5::SafeList
instead.
Thanks to @JuanitoFatas for submitting these changes in #164 and for making the language used in Loofah more inclusive.