code-farmer-i / vue-markdown-editor

A markdown editor built on Vue
https://code-farmer-i.github.io/vue-markdown-editor/
MIT License
1.1k stars 109 forks source link

无法识别iframe标签 #233

Closed stone-98 closed 1 year ago

stone-98 commented 1 year ago

我采用嵌入b站的视频,显示到编辑器中,发现vue-markdown-editor无法识别,是目前不支持这种形式嘛? 嵌入代码如下所示:

<iframe src="//player.bilibili.com/player.html?aid=528220392&bvid=BV16M411g7na&cid=1117967815&page=1" scrolling="no" border="0" frameborder="no" framespacing="0" allowfullscreen="true"> </iframe>
code-farmer-i commented 1 year ago

iframe默认会被xss过滤,参考文档配置xss白名单,xss配置 例如:

VMdEditor.xss.extend({
  // 扩展白名单
  whiteList: {
    iframe: ['src'],
  },
});