forked from GNUsocial/gnu-social
44c10bb2aa
purify oembed html and don't allow cdata hopefully we never need stuff in cdata reason for this is that this link serves javascript in its oembed data: https://www.maketecheasier.com/switch-windows-10-to-linux/ see: https://www.maketecheasier.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fwww.maketecheasier.com%2Fswitch-windows-10-to-linux%2F i don't feel we want that in our database. See merge request !79 |
||
---|---|---|
.. | ||
oembedhelper.php | ||
opengraphhelper.php |