enable xss filtering and smart quote replacement in markdown

This commit is contained in:
Devin Howard 2016-10-09 10:20:17 +08:00
parent 9ac24f7468
commit ba9e26bc05

View file

@ -123,7 +123,9 @@ const Util = {
return (url.match(/^https?:\/\/(?:www\.)?youtube.com\/watch\?(?=[^?]*v=\w+)(?:[^\s?]+)?$/) != null)
},
mdToHTML: text => {
return new HtmlRenderer().render(new Parser().parse(text))
// use safe: true to filter xss
return new HtmlRenderer({ safe: true, smart: true })
.render(new Parser().parse(text))
}
}