dwyl / github-backup

:octocat: :back: 🆙 Backup your GitHub Issues so you can still work when (they/you are) offline.
https://github-backup.herokuapp.com
GNU General Public License v2.0
31 stars 3 forks source link

Stop script injections from rendering in comments #95

Closed Cleop closed 6 years ago

Cleop commented 6 years ago

At the moment I can add a script to a comment on github and whilst it won't render on github, it will on our site.

Cleop commented 6 years ago

https://hex.pm/packages/html_sanitize_ex will apparently help to solve this!

nelsonic commented 6 years ago

@Cleop looks good. thanks for resolving. 👍