Page MenuHomePhabricator

"Readme.md"-Display does not render inline HTML
Closed, WontfixPublic

Description

When I commit a Readme.md that was generated with org-mode, there is quite a bit of HTML embedded.

The Renderer in Diffusion does not seem to support this, and displays the raw HTML code.

Is there a way to change that?

Event Timeline

timor updated the task description. (Show Details)
timor added a project: Diffusion.
timor added a subscriber: timor.
epriestley claimed this task.
epriestley added a subscriber: epriestley.

There's no way to do this. It would allow anyone with commit access to XSS other users and take over their accounts.

Would stripping the tags from the md file during rendering be a solution? It would be sufficient here...

Not as an upstream solution.