mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-08-12 18:10:43 +09:00
d3f22d78e1
* Bump thruster 0.1.15 → 0.1.23 * Scrub disallowed attributes on allowed tags in message rendering SanitizeTags removes disallowed tags from message presentation, but attributes on the tags it allows passed through untouched. Extend the content-filter chain with a SanitizeAttributes filter that runs Rails' safe-list sanitizer over the remaining markup, stripping event-handler attributes and unsafe URI schemes as defense-in-depth alongside the existing Content-Security-Policy. Running it after SanitizeTags with the same allowed-tags list makes the sanitizer's tag pass a no-op, preserving SanitizeTags' remove-not-unwrap semantics while scrubbing attributes. The attribute allowlist is the standard ActionText set (which keeps attachments intact) plus class, which presentation styling relies on.