Skip to content

Sanitize URI scheme inside <link> elements#80

Merged
Alkarex merged 1 commit into
FreshRSS:freshrssfrom
Inverle:link-scheme-sanitization
Jun 13, 2026
Merged

Sanitize URI scheme inside <link> elements#80
Alkarex merged 1 commit into
FreshRSS:freshrssfrom
Inverle:link-scheme-sanitization

Conversation

@Inverle

@Inverle Inverle commented Jun 13, 2026

Copy link
Copy Markdown
Member

Follow-up of #65

@Inverle Inverle requested a review from Alkarex June 13, 2026 16:01
@Alkarex Alkarex merged commit 383c69d into FreshRSS:freshrss Jun 13, 2026
10 checks passed
@Inverle Inverle deleted the link-scheme-sanitization branch June 13, 2026 18:14
Alkarex added a commit to FreshRSS/FreshRSS that referenced this pull request Jun 13, 2026
Follow-up of #7924
FreshRSS/simplepie#80
FreshRSS/simplepie#65

* SimplePie: Disallow `javascript:` URI protocol

* Sync SimplePie

* Update code to work with SimplePie again

* Partial revert previous commit

* Bump SimplePie

---------

Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants