0
Fork 0
mirror of https://codeberg.org/forgejo/forgejo.git synced 2025-02-28 08:46:02 -05:00
forgejo/modules
Gusted 80e05a8245
[GITEA] Use restricted sanitizer for repository description
- Currently the repository description uses the same sanitizer as a
normal markdown document. This means that element such as heading and
images are allowed and can be abused.
- Create a minimal restricted sanitizer for the repository description,
which only allows what the postprocessor currently allows, which are
links and emojis.
- Added unit testing.
- Resolves https://codeberg.org/forgejo/forgejo/issues/1202
- Resolves https://codeberg.org/Codeberg/Community/issues/1122

(cherry picked from commit a8afa4cd18)
(cherry picked from commit 0238587c51)
(cherry picked from commit a8c7bbf728)
2023-10-02 19:23:42 +02:00
..
actions [CI] Search .forgejo/workflows first 2023-10-02 16:13:40 +02:00
activitypub make writing main test easier (#27270) 2023-09-28 01:38:53 +00:00
analyze
assetfs Use Set[Type] instead of map[Type]bool/struct{}. (#26804) 2023-08-30 06:55:25 +00:00
auth [SECURITY] default to pbkdf2 with 320,000 iterations 2023-10-02 17:06:22 +02:00
avatar
base
cache
charset
container
context Improvements of releases list and tags list (#25859) 2023-09-28 13:21:47 +00:00
contexttest Avoid double-unescaping of form value (#26853) 2023-09-01 12:01:36 +00:00
csv
doctor doctor: delete action entries without existing user (#27292) 2023-09-28 03:03:08 +00:00
emoji
eventsource More db.DefaultContext refactor (#27265) 2023-09-29 12:12:54 +00:00
generate
git Support .git-blame-ignore-revs file (#26395) 2023-09-16 17:42:34 +00:00
gitgraph More db.DefaultContext refactor (#27265) 2023-09-29 12:12:54 +00:00
graceful
hcaptcha
highlight
hostmatcher
html
httpcache
httplib
indexer [CI] disable meilisearch/elasticsearch test, no server yet in CI 2023-10-02 16:13:40 +02:00
issue/template
json
label
lfs Refactor lfs requests (#26783) 2023-09-18 08:40:50 +00:00
log Reduce some allocations in type conversion (#26772) 2023-08-29 00:43:16 +08:00
markup [GITEA] Use restricted sanitizer for repository description 2023-10-02 19:23:42 +02:00
mcaptcha
metrics Reduce usage of db.DefaultContext (#27073) 2023-09-14 17:09:32 +00:00
migration
nosql
options
packages Use docs.gitea.com instead of docs.gitea.io (#26739) 2023-08-27 11:59:12 +00:00
paginator
pprof
private [CLI] implement forgejo-cli 2023-10-02 16:13:39 +02:00
process
proxy
proxyprotocol
public
queue [CI] disable redis test, no redis server yet in CI 2023-10-02 16:13:40 +02:00
recaptcha
references Replace 'userxx' with 'orgxx' in all test files when the user type is org (#27052) 2023-09-14 02:59:53 +00:00
regexplru
repository make writing main test easier (#27270) 2023-09-28 01:38:53 +00:00
secret
session Next round of db.DefaultContext refactor (#27089) 2023-09-16 14:39:12 +00:00
setting [GITEA] notifies admins on new user registration 2023-10-02 19:23:42 +02:00
sitemap
ssh restrict certificate type for builtin SSH server (#26789) 2023-09-01 13:45:22 +00:00
storage [CI] Forgejo Actions based CI for PR & branches 2023-10-02 16:13:40 +02:00
structs [FEAT] allow setting the update date on issues and comments 2023-10-02 17:06:23 +02:00
svg
sync
system make writing main test easier (#27270) 2023-09-28 01:38:53 +00:00
templates More db.DefaultContext refactor (#27265) 2023-09-29 12:12:54 +00:00
test Move web/api context related testing function into a separate package (#26859) 2023-09-01 11:26:07 +00:00
testlogger
timeutil
translation
turnstile
typesniffer
updatechecker
upload
uri
user
util Refactor lfs requests (#26783) 2023-09-18 08:40:50 +00:00
validation [GITEA] add option for banning dots in usernames 2023-10-02 19:00:59 +02:00
web [GITEA] add option for banning dots in usernames 2023-10-02 19:00:59 +02:00
webhook