Pass rendered markdown through additional sanitizer

Uses insane to process rendered markdown. Adds an additional level of protection for context injections
This commit is contained in:
Matt Bierner
2019-08-19 19:40:31 -07:00
parent 6ccd57138a
commit e9b4a91e4a
6 changed files with 552 additions and 1 deletions

View File

@@ -50,6 +50,7 @@ const indentationFilter = [
'!src/vs/css.js',
'!src/vs/css.build.js',
'!src/vs/loader.js',
'!src/vs/base/common/insane/insane.js',
'!src/vs/base/common/marked/marked.js',
'!src/vs/base/node/terminateProcess.sh',
'!src/vs/base/node/cpuUsage.sh',
@@ -131,6 +132,7 @@ const eslintFilter = [
'!src/vs/nls.js',
'!src/vs/css.build.js',
'!src/vs/nls.build.js',
'!src/**/insane.js',
'!src/**/marked.js',
'!**/test/**'
];