feat: sanitize reply content
This commit is contained in:
parent
2e06e34a7b
commit
e71dbf15f3
1 changed files with 2 additions and 1 deletions
|
@ -62,7 +62,8 @@ function createRepliesBlock(replies, heading) {
|
|||
).toLocaleDateString()}</a><div class="clear-both"></div>`;
|
||||
const card = document.createElement("div");
|
||||
card.className = "reply-card";
|
||||
card.innerHTML = reply.content.html;
|
||||
const sanitizer = new Sanitizer();
|
||||
card.setHTML(reply.content.html, { sanitizer });
|
||||
card.insertBefore(author, card.firstChild);
|
||||
cell.appendChild(card);
|
||||
repliesTable.append(row);
|
||||
|
|
Loading…
Reference in a new issue