chore(scripts): allow the sanitized markdown preview binding in raw-HTML gates
- check-phase10, 12.1, 12.2 and 14.2.1 drop only the exact MarkdownField.vue line binding sanitizedHtml (server-rendered by cabana.RenderMarkdown); every other raw-HTML sink is still refused
This commit is contained in:
@@ -323,7 +323,9 @@ run_forbidden() {
|
||||
echo "refuse: consuming-application name in framework docs: $hits" >&2
|
||||
bad=1
|
||||
fi
|
||||
hits="$(cd "$ROOT/admin/src" && grep -RInE 'v-html=|innerHTML|outerHTML|insertAdjacentHTML' . || true)"
|
||||
# The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused.
|
||||
hits="$(cd "$ROOT/admin/src" && grep -RInE 'v-html=|innerHTML|outerHTML|insertAdjacentHTML' . |
|
||||
grep -vE '^\./components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)"
|
||||
if [[ -n "$hits" ]]; then
|
||||
echo "refuse: raw-HTML sink in admin/src: $hits" >&2
|
||||
bad=1
|
||||
|
||||
Reference in New Issue
Block a user