From 0d64da48a71137f459a930e11cda54d46e3b6d51 Mon Sep 17 00:00:00 2001 From: Winnie Hellmann Date: Fri, 9 Nov 2018 14:16:11 +0100 Subject: Configure mermaid to not render HTML content in diagrams (cherry picked from commit f2e9f22f7d3d84abeea5ba2918ee5ffcc55f2dad) Conflicts: app/assets/javascripts/behaviors/markdown/render_mermaid.js --- app/assets/javascripts/behaviors/markdown/render_mermaid.js | 3 +++ changelogs/unreleased/security-mermaid-xss.yml | 5 +++++ 2 files changed, 8 insertions(+) create mode 100644 changelogs/unreleased/security-mermaid-xss.yml diff --git a/app/assets/javascripts/behaviors/markdown/render_mermaid.js b/app/assets/javascripts/behaviors/markdown/render_mermaid.js index 56b1896e9f1..4abea532d56 100644 --- a/app/assets/javascripts/behaviors/markdown/render_mermaid.js +++ b/app/assets/javascripts/behaviors/markdown/render_mermaid.js @@ -25,6 +25,9 @@ export default function renderMermaid($els) { }, // mermaidAPI options theme: 'neutral', + flowchart: { + htmlLabels: false, + }, }); $els.each((i, el) => { diff --git a/changelogs/unreleased/security-mermaid-xss.yml b/changelogs/unreleased/security-mermaid-xss.yml new file mode 100644 index 00000000000..bcf93ef37ff --- /dev/null +++ b/changelogs/unreleased/security-mermaid-xss.yml @@ -0,0 +1,5 @@ +--- +title: Configure mermaid to not render HTML content in diagrams +merge_request: +author: +type: security -- cgit v1.2.1