make sure that markdown uses safe mode (#2961)
This commit is contained in:
@@ -61,7 +61,7 @@ final class MarkdownExtension implements RuntimeExtensionInterface
|
||||
}
|
||||
|
||||
if ($this->isMarkdownEnabled()) {
|
||||
$content = $this->markdown->toHtml($content, false);
|
||||
$content = $this->markdown->toHtml($content);
|
||||
} elseif ($fullLength) {
|
||||
$content = '<p>' . nl2br($content) . '</p>';
|
||||
}
|
||||
@@ -112,7 +112,7 @@ final class MarkdownExtension implements RuntimeExtensionInterface
|
||||
}
|
||||
|
||||
if ($this->isMarkdownEnabled()) {
|
||||
return $this->markdown->toHtml($content, false);
|
||||
return $this->markdown->toHtml($content);
|
||||
}
|
||||
|
||||
return nl2br($content);
|
||||
@@ -126,6 +126,6 @@ final class MarkdownExtension implements RuntimeExtensionInterface
|
||||
*/
|
||||
public function markdownToHtml(string $content): string
|
||||
{
|
||||
return $this->markdown->toHtml($content, false);
|
||||
return $this->markdown->toHtml($content);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -33,7 +33,12 @@ final class Markdown
|
||||
*/
|
||||
public function toHtml(string $text, bool $safe = true): string
|
||||
{
|
||||
$this->parser->setSafeMode($safe);
|
||||
if ($safe !== true) {
|
||||
@trigger_error('Only safe mode is supported in Markdown since 1.16.3 to prevent XSS attacks. Parameter $safe will be removed with 2.0', E_USER_DEPRECATED);
|
||||
}
|
||||
|
||||
$this->parser->setSafeMode(true);
|
||||
$this->parser->setMarkupEscaped(true);
|
||||
|
||||
return $this->parser->text($text);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user