diff options
author | Winnie Hellmann <winnie@gitlab.com> | 2018-11-09 14:16:11 +0100 |
---|---|---|
committer | Winnie Hellmann <winnie@gitlab.com> | 2018-11-19 14:46:18 +0100 |
commit | ae34dd6eb7a77a4fe7f9c1aea414bf014747ba25 (patch) | |
tree | ea332a35daf038ad446577af0edd9f9607181c33 | |
parent | d2b7ea9c1aacb3ef2e798194c7f69a1a92adca43 (diff) | |
download | gitlab-ce-ae34dd6eb7a77a4fe7f9c1aea414bf014747ba25.tar.gz |
Configure mermaid to not render HTML content in diagrams
(cherry picked from commit f2e9f22f7d3d84abeea5ba2918ee5ffcc55f2dad)
-rw-r--r-- | app/assets/javascripts/behaviors/markdown/render_mermaid.js | 3 | ||||
-rw-r--r-- | changelogs/unreleased/security-mermaid-xss.yml | 5 |
2 files changed, 8 insertions, 0 deletions
diff --git a/app/assets/javascripts/behaviors/markdown/render_mermaid.js b/app/assets/javascripts/behaviors/markdown/render_mermaid.js index 720f30e18e6..35380ca49fb 100644 --- a/app/assets/javascripts/behaviors/markdown/render_mermaid.js +++ b/app/assets/javascripts/behaviors/markdown/render_mermaid.js @@ -26,6 +26,9 @@ export default function renderMermaid($els) { }, // mermaidAPI options theme: 'neutral', + flowchart: { + htmlLabels: false, + }, }); $els.each((i, el) => { diff --git a/changelogs/unreleased/security-mermaid-xss.yml b/changelogs/unreleased/security-mermaid-xss.yml new file mode 100644 index 00000000000..bcf93ef37ff --- /dev/null +++ b/changelogs/unreleased/security-mermaid-xss.yml @@ -0,0 +1,5 @@ +--- +title: Configure mermaid to not render HTML content in diagrams +merge_request: +author: +type: security |