Open steph643 opened 6 years ago
I'm having this same issue, but actually this is what I see on my end:
stripIgnoreTagBody: ['script']
Here is the onTag defincitonl
function onTag(tag) {
if (tag === 'script') {
return "";
}
return undefined;
}
Here are the results: | case | original data | option 1 output | option 2 output | option 3 output |
---|---|---|---|---|---|
1 | \<script\>alert(1)\<script\> | alert(1) | |||
2 | \<script/\> | [removed] |
case 1, option 2 ... that's an empty string case 2, option 3 ... that's an empty string.
I'm sure there are more options that I can try, but I could not find a configuration that would clear out both strings with one set of options.
Consider the following code:
I believe it should output this:
But instead it displays this: