kawa-kokosowa / bubblebbs

Text BBS 🗣️ with authenticated 🔒🆔 posts 🗨️ and no registration 🚫✍️
http://bubblebbs.cafe
MIT License
17 stars 3 forks source link

Security: what is mdx_bleach even doing? #129

Open kawa-kokosowa opened 6 years ago

kawa-kokosowa commented 6 years ago

Need to have a clearer process for how a post is parsed, it's a mess rn and will make security issues pop up

kawa-kokosowa commented 6 years ago

seems to only bleach when its parsing the markdown ergo why its done first step and the rest steps are adding in features that weren't parsed