vercte β€” 5/9/2022, 5:43:08 PM

@jeffalo /chat may have a few xss vulnerabilities, but just HTML, no scripting (good job you are good at this)

β™₯ 1 ↩ 0 πŸ’¬ 4 comments

comments

jeffalo:

it’s intended :) it works the same as posts & comments, and is properly sanitized by dompurify

5/9/2022, 5:57:19 PM
vercte:

ahh ok (makes sense)

time to look at DOMpurify

5/12/2022, 1:03:25 AM
vercte:

just wondering, does it allow style or no?

5/12/2022, 1:05:57 AM
jeffalo:

no

5/12/2022, 6:47:18 AM