mirror of
https://github.com/TeamPiped/Piped.git
synced 2025-12-26 06:30:21 +00:00
Fix severe vulnerability in case of a malicious Piped/YouTube server.
This commit is contained in:
@@ -11,6 +11,8 @@ import("uikit/dist/js/uikit-core.min");
|
||||
import router from "@/router/router";
|
||||
import App from "./App.vue";
|
||||
|
||||
import DOMPurify from 'dompurify';
|
||||
|
||||
import("./registerServiceWorker");
|
||||
|
||||
const mixin = {
|
||||
@@ -58,6 +60,9 @@ const mixin = {
|
||||
return response.json();
|
||||
});
|
||||
},
|
||||
purifyHTML(original) {
|
||||
return DOMPurify.sanitize(original);
|
||||
}
|
||||
},
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user