From 7d1803ac8286fa994a2e995424057bbd0ff24562 Mon Sep 17 00:00:00 2001 From: peteruithoven Date: Sat, 21 May 2022 13:55:49 +0200 Subject: [PATCH] Allow more iframe attributes --- server/modules/rendering/html-security/renderer.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/modules/rendering/html-security/renderer.js b/server/modules/rendering/html-security/renderer.js index 3bf9b2dc..d3421057 100644 --- a/server/modules/rendering/html-security/renderer.js +++ b/server/modules/rendering/html-security/renderer.js @@ -29,7 +29,7 @@ module.exports = { if (config.allowIFrames) { allowedTags.push('iframe') - allowedAttrs.push('allow') + allowedAttrs.push('allow', 'frameborder', 'allowfullscreen') } input = DOMPurify.sanitize(input, {