fix: security html module removes allow attribute from iframes (#2354)

* fix: secure html module removes allowfullscreen, allow and frameborder attributes from iframes
* Apply suggestions from code review
fix: remove deprecated attributes for iframe in secure html module

Co-authored-by: Nicolas Giard <github@ngpixel.com>
This commit is contained in:
Иван 2020-09-13 20:55:32 +03:00 committed by GitHub
parent 660b78d9e2
commit 79c5b8fac2
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -29,6 +29,7 @@ module.exports = {
if (config.allowIFrames) { if (config.allowIFrames) {
allowedTags.push('iframe') allowedTags.push('iframe')
allowedAttrs.push('allow')
} }
input = DOMPurify.sanitize(input, { input = DOMPurify.sanitize(input, {