halfer / awooga-app

Web application to report coding tutorials of non-optimal quality
0 stars 0 forks source link

Markdown HTML still needs purifying #20

Closed halfer closed 9 years ago

halfer commented 9 years ago

Oops! I discovered today that the output of the Markdown parser still needs filtering for XSS. I've done that just now, seems to work.

It needs some unit tests, so I've added in a @todo note in the relevant class.