Skip to content

markdown: Sanitize HTML #1615

Answered by gsantner
easyaspi314 asked this question in Ideas
Feb 20, 2022 · 2 comments · 1 reply
Discussion options

You must be logged in to vote

Hello,

at Markor it is wanted/expected behaviour. Specifically, there are even options to globally inject any custom javascript and css. And..I know users do add custom js and css to some files, so the logic/style only applies specifically to these files in addition to globals. By the way, theres more than just Markdown at Markor, you can also open normal .html files just fine "as is".

Most Markdown viewers

As you say, Most, but not all. It is especially bad to see that most sanitizers also break non-malicious things. One painful recent example - wanted to use NextCloud PicoCMS - and many of the things don't work. Simple things. Like displaying small webp favicon icon inline.

If you are…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by gsantner
Comment options

You must be logged in to vote
1 reply
@gsantner
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #1615 on February 20, 2022 12:08.