csvalpha / amber-api

https://csvalpha.nl
MIT License
4 stars 4 forks source link

Camofy HTML content for static-pages #466

Open DrumsnChocolate opened 1 day ago

DrumsnChocolate commented 1 day ago

camofication of insecure resources currently only happens for markdown. We should have a look at whether this is also possible for HTML. Where did this come from? A user found out it is possible to use HTML in static-page content, and subsequently tried to use images in this HTML. Sadly, this resulted in a failure to load images. We discovered that this is due to the image sources not being camofied, whereas with markdown content the image sources are camofied.

So we should either not permit HTML content in static-pages, or we should also camofy HTML content.