summaryrefslogtreecommitdiff
path: root/app/assets/javascripts
diff options
context:
space:
mode:
authorGitLab Bot <gitlab-bot@gitlab.com>2022-02-03 11:35:58 +0000
committerGitLab Bot <gitlab-bot@gitlab.com>2022-02-03 11:36:09 +0000
commiteb25ac12499d70f7ebd59b64857e6901a5c32972 (patch)
treee6755949ec3f059fcbe5110213cea3d2ef07a506 /app/assets/javascripts
parent33bbb6aa7b6369fea0037f3d8a9243824e48f64f (diff)
downloadgitlab-ce-eb25ac12499d70f7ebd59b64857e6901a5c32972.tar.gz
Add latest changes from gitlab-org/security/gitlab@14-7-stable-ee
Diffstat (limited to 'app/assets/javascripts')
-rw-r--r--app/assets/javascripts/notebook/cells/output/html.vue3
1 files changed, 3 insertions, 0 deletions
diff --git a/app/assets/javascripts/notebook/cells/output/html.vue b/app/assets/javascripts/notebook/cells/output/html.vue
index ca02ee18dd1..2d1d8845e41 100644
--- a/app/assets/javascripts/notebook/cells/output/html.vue
+++ b/app/assets/javascripts/notebook/cells/output/html.vue
@@ -30,6 +30,9 @@ export default {
},
safeHtmlConfig: {
ADD_TAGS: ['use'], // to support icon SVGs
+ FORBID_TAGS: ['style'],
+ FORBID_ATTR: ['style'],
+ ALLOW_DATA_ATTR: false,
},
};
</script>