fix: fix xss problem when render iframe

chore/cli-prune-script
moonrailgun 7 months ago
parent d57a878a99
commit c1365f2b82

@ -46,6 +46,11 @@ export const Markdown: React.FC<{
), ),
iframe: (props) => { iframe: (props) => {
let src = props.src; let src = props.src;
if (src?.includes('javascript')) {
return <div>not support run javascript</div>;
}
if (src && src.includes('?')) { if (src && src.includes('?')) {
src += '&autoplay=0'; // make sure media autoplay is false src += '&autoplay=0'; // make sure media autoplay is false
} }

Loading…
Cancel
Save