diff --git a/lib/util.php b/lib/util.php index 157d36c71c..20306635af 100644 --- a/lib/util.php +++ b/lib/util.php @@ -581,7 +581,8 @@ function common_purify($html) $config = array('safe' => 1, // means that elements=* means elements=*-applet-embed-iframe-object-script or so 'elements' => '*', - 'deny_attribute' => 'id,style,on*'); + 'deny_attribute' => 'id,style,on*', + 'cdata' => 1); // Remove more elements than what the 'safe' filter gives (elements must be '*' before this) // http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/htmLawed_README.htm#s3.6 diff --git a/plugins/Oembed/lib/oembedhelper.php b/plugins/Oembed/lib/oembedhelper.php index 7abd76109a..b0527b7529 100644 --- a/plugins/Oembed/lib/oembedhelper.php +++ b/plugins/Oembed/lib/oembedhelper.php @@ -158,7 +158,15 @@ class oEmbedHelper if(isset($key)) { $params['key'] = common_config('oembed','apikey'); } - return HTTPClient::quickGetJson($api, $params); + + $oembed_data = HTTPClient::quickGetJson($api, $params); + + // purify html + if(isset($oembed_data->html)) { + $oembed_data->html = common_purify($oembed_data->html); + } + + return $oembed_data; } /** @@ -211,4 +219,4 @@ class oEmbedHelper_DiscoveryException extends oEmbedHelper_Exception { return parent::__construct('No oEmbed discovery data.', 0, $previous); } -} +} \ No newline at end of file