mirror of
https://github.com/9001/copyparty.git
synced 2025-08-17 09:02:15 -06:00
by running dompurify after marked.parse if plugins are not enabled; adds no protection against the more practical approach of just putting a malicious <script> in an html file and uploading that, but one footgun less is one less footgun |
||
---|---|---|
.. | ||
codemirror.patch | ||
Dockerfile | ||
easymde-ln.patch | ||
easymde-marked6.patch | ||
easymde.patch | ||
genprism.py | ||
genprism.sh | ||
Makefile | ||
markdown-it.patch | ||
marked-ln.patch | ||
marked.patch | ||
mini-fa.css | ||
mini-fa.sh | ||
shiftbase.py | ||
showdown.patch | ||
zopfli.makefile |