diff options
| author | Nicholas Johnson <> | 2026-09-18 00:00:00 +0000 |
|---|---|---|
| committer | Nicholas Johnson <> | 2026-09-19 16:34:32 -0400 |
| commit | 61d07d87a9b54cd102699e065a349d5c3fc4a06fbe7a96c255e43aa182c02be7 (patch) | |
| tree | 381fa4edb4bc9a5ac37749dcc26faa19f16b8c8a49a544caa13d239f7b730d03 /assets/static | |
| parent | 424afe0f8fed829758cc4d09722b4cfd98268734f82b799962369478389cf5dc (diff) | |
| download | hugo-theme-journal-61d07d87a9b54cd102699e065a349d5c3fc4a06fbe7a96c255e43aa182c02be7.tar.gz hugo-theme-journal-61d07d87a9b54cd102699e065a349d5c3fc4a06fbe7a96c255e43aa182c02be7.zip | |
Drop scripting URL schemes from links and images
Both render hooks passed the destination through safeURL, which bypasses
the sanitising that html/template would otherwise apply, so a
javascript: or data:text/html destination in Markdown became a live
scripting URL in the page. That matters for any site built from content
its author did not write.
safeURL cannot simply be dropped: it is what allows gemini:// and other
schemes html/template does not recognise to survive, which this theme
depends on. Reject the scripting schemes explicitly instead, render the
link text on its own, and warn during the build so the author can see
what was dropped. data: is still allowed for images, where it is a
legitimate way to inline one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'assets/static')
0 files changed, 0 insertions, 0 deletions
