From c74cc3ad37a2e334d3433a02679ebbf6e02cb4f8 Mon Sep 17 00:00:00 2001 From: John Bowdre Date: Mon, 15 Jan 2024 14:53:35 -0600 Subject: [PATCH] rss: strip potentially-unsafe style elements --- layouts/_default/rss.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/layouts/_default/rss.xml b/layouts/_default/rss.xml index e1a96ba..b255c9f 100644 --- a/layouts/_default/rss.xml +++ b/layouts/_default/rss.xml @@ -44,6 +44,7 @@ {{- $content := replaceRE "a href=\"(#.*?)\"" (printf "%s%s%s" "a href=\"" .Permalink "$1\"") .Content -}} {{- $content = replaceRE "img src=\"(.*?)\"" (printf "%s%s%s" "img src=\"" .Permalink "$1\"") $content -}} {{- $content = replaceRE "" "" $content -}} + {{- $content = replaceRE `-moz-tab-size:\d;-o-tab-size:\d;tab-size:\d` "" $content -}} {{ $content | html }} {{ end }}