mjhouse / bowtie

The bowtie social media website
GNU General Public License v3.0
0 stars 0 forks source link

Verify that js included in post body won't be executed when the post is displayed #14

Closed mjhouse closed 4 years ago

mjhouse commented 4 years ago

the safe filter in Tera may also un-escape Javascript and allow it to execute.

mjhouse commented 4 years ago

Verified that this does NOT happen by:

Javascript and <script> tags were included as plain text even with the 'safe' filter.