From bacbe4f5430f9fdafbf4e31a2fa6b67877aa24f1 Mon Sep 17 00:00:00 2001 From: NGPixel Date: Sat, 21 Mar 2020 12:49:25 -0400 Subject: [PATCH] fix: whitelist task list checkboxes --- server/modules/rendering/html-security/renderer.js | 2 ++ 1 file changed, 2 insertions(+) diff --git a/server/modules/rendering/html-security/renderer.js b/server/modules/rendering/html-security/renderer.js index 8ef20261..815f8db1 100644 --- a/server/modules/rendering/html-security/renderer.js +++ b/server/modules/rendering/html-security/renderer.js @@ -21,7 +21,9 @@ module.exports = { h5: ['class', 'id', 'style'], h6: ['class', 'id', 'style'], img: ['alt', 'class', 'draggable', 'height', 'src', 'style', 'width'], + input: ['class', 'disabled', 'type', 'checked', 'id'], kbd: ['class'], + label: ['class', 'id', 'for'], li: ['class', 'style'], mark: ['class', 'style'], ol: ['class', 'style'],