- Jan 12, 2023
-
-
flxy authored
-
- Dec 24, 2022
-
- Sep 18, 2022
-
-
tusooa authored
-
- Jul 31, 2022
-
-
HJ authored
-
- May 22, 2022
-
-
HJ authored
This reverts merge request !1526
-
- May 21, 2022
-
-
iamtakingiteasy authored
-
- Apr 30, 2022
- Feb 22, 2022
-
-
HJ authored
-
- Nov 16, 2021
-
-
rinpatch authored
In January 2020 Pleroma backend stopped escaping HTML in display names and passed that responsibility on frontends, compliant with Mastodon's version of Mastodon API [1]. Pleroma-FE was subsequently modified to escape the display name [2], however only in the "name_html" field. This was fine however, since that's what the code rendering display names used. However, 2 months ago an MR [3] refactoring the way the frontend does emoji and mention rendering was merged. One of the things it did was moving away from doing emoji rendering in the entity normalizer and use the unescaped 'user.name' in the rendering code, resulting in HTML injection being possible again. This patch escapes 'user.name' as well, as far as I can tell there is no actual use for an unescaped display name in frontend code, especially when it comes from MastoAPI, where it is not supposed to be HTML. [1]: !1052 [2]: pleroma!2167 [3]: !1392
-
- Dec 02, 2020
-
-
Shpuld Shpludson authored
-
- Nov 18, 2020
-
-
Shpuld Shpludson authored
-
- Oct 20, 2020
- Jul 08, 2020
-
-
streamline profile image api, update reset ui for all profile images to match avatar, remove unnecessary stuff
-
- Jun 21, 2020
-
-
Sergey Suprunenko authored
-
- Jun 19, 2020
-
-
kPherox authored
-
- Jun 09, 2020
-
-
kPherox authored
-
- May 25, 2020
-
-
HJ authored
-
- May 10, 2020
-
-
HJ authored
-
- May 03, 2020
-
-
HJ authored
-