Robin Ward
|
4dc20e6855
|
FIX: Sanitize custom quote attributes
|
2014-04-21 10:19:39 -04:00 |
|
Robin Ward
|
ed6e2b1d79
|
Remove Zalgo API from Discourse.Mention:
http://blog.izs.me/post/59142742143/designing-apis-for-asynchrony -
Thanks @riking for finding it.
|
2014-04-14 16:51:18 -04:00 |
|
Régis Hanol
|
e663d78104
|
SECURITY: sanitize markdown urls (prevent XSS)
|
2014-03-27 15:34:35 +01:00 |
|
riking
|
86774fa5c1
|
Simplify return statements
|
2014-03-18 18:23:15 -07:00 |
|
riking
|
593f5df503
|
Corrections to JSDoc
|
2014-03-18 18:19:20 -07:00 |
|
Robin Ward
|
6143753fef
|
Support uppercase bbcode too.
|
2014-03-03 11:59:57 -05:00 |
|
Robin Ward
|
3d62df51a6
|
FIX: Broken MDTest + Fix for removing leading spaces in a code block
|
2014-02-11 17:27:24 -05:00 |
|
Robin Ward
|
745cd0f4e9
|
FIX: Removes console.log
|
2014-01-22 11:07:19 -05:00 |
|
Robin Ward
|
e2c361f353
|
FIX: Indented code blocks followed by <blockquote> weren't working.
|
2014-01-21 16:18:20 -05:00 |
|
Robin Ward
|
3c3449aa1b
|
Revert "New API for replacing elements in the final JsonML. Also changes spoiler"
This reverts commit 6b9b2d3d6a.
We have come up with a better solution that does not involve HTML
parsing.
|
2014-01-21 12:04:58 -05:00 |
|
Robin Ward
|
6b9b2d3d6a
|
New API for replacing elements in the final JsonML. Also changes spoiler
tag handling to be more robust with repsect to HTML content.
|
2014-01-20 15:15:50 -05:00 |
|
Régis Hanol
|
ad8755aa70
|
BUGFIX: inline spoiler for text, block spoiler for images
|
2014-01-15 00:53:06 +01:00 |
|
Régis Hanol
|
70161498b6
|
BUGFIX: spoiler tag on lightboxed images wasn't working
|
2014-01-12 19:38:46 +01:00 |
|
Robin Ward
|
a502266c42
|
Enable JSHINT's unused option. It caught a bunch of suspicious stuff which is fixed in this commit.
|
2013-12-30 13:30:22 -05:00 |
|
Robin Ward
|
4f7d440fa4
|
Remove unused hook.
|
2013-12-19 14:43:36 -05:00 |
|
Sam
|
5bd595c9a6
|
FEATURE: default_code_lang for syntax highlighting is configurable
|
2013-12-17 12:08:29 +11:00 |
|
Robin Ward
|
2326d4ceb7
|
FIX: text node emitters should always take strings as parameters even if they
return JsonML.
|
2013-12-16 15:41:46 -05:00 |
|
Robin Ward
|
a7a7387da1
|
Automatically convert some quotes to blockquotes
|
2013-12-13 15:31:25 -05:00 |
|
Régis Hanol
|
9b6538832d
|
whitelist google.com/maps iframes
|
2013-11-29 18:08:53 +01:00 |
|
Robin Ward
|
549060867d
|
Updated documentation for inlineRegexp
|
2013-11-25 11:35:28 -05:00 |
|
Robin Ward
|
127c3d0e21
|
FIX: Performance regression on Markdown renderer.
|
2013-11-08 11:42:26 -05:00 |
|
Robin Ward
|
ac9a763ab3
|
FIX: Extra space before tags in blockquotes
|
2013-11-07 16:06:50 -05:00 |
|
Robin Ward
|
902b6bc79f
|
FIX: Oneboxes were losing formatting in preview after being cached.
|
2013-11-06 15:58:41 -05:00 |
|
Robin Ward
|
b8e63719f8
|
FIX: Don't autolink within a markdown link.
|
2013-11-04 14:24:40 -05:00 |
|
Robin Ward
|
13fa473c6d
|
Fix JSHINT
|
2013-10-22 11:33:45 -04:00 |
|
Robin Ward
|
e2845f7f16
|
Restrict SIZE= to numbers
|
2013-10-22 11:08:13 -04:00 |
|
Robin Ward
|
b51fb4d3fb
|
Sync up with markdown-js + our changes
|
2013-10-21 15:06:58 -04:00 |
|
Robin Ward
|
7a5c3bfcd8
|
whitelist acceptable syntax highlighting classes
|
2013-10-21 13:11:10 -04:00 |
|
Robin Ward
|
d10f9f756f
|
FIX: [code] blocks with # headers within
|
2013-10-21 12:12:58 -04:00 |
|
Robin Ward
|
1783089d64
|
FIX: [quote] without params was failing.
|
2013-10-21 11:12:47 -04:00 |
|
Robin Ward
|
db2283b9d3
|
FIX: JSHint
|
2013-10-18 17:48:19 -04:00 |
|
Robin Ward
|
1113b8d7a8
|
FIX: Don't double sanitize values, allow blockquotes with leading text
|
2013-10-18 17:34:54 -04:00 |
|
Robin Ward
|
d7182d0b14
|
FIX: Only wrap inline html tags in <p>
|
2013-10-18 15:21:05 -04:00 |
|
Robin Ward
|
67771d6bdf
|
FIX: New line after blockquote
|
2013-10-16 10:28:48 -04:00 |
|
Robin Ward
|
f27413219e
|
Support for MDTest
|
2013-10-16 10:28:42 -04:00 |
|
Robin Ward
|
5281b7f80c
|
Upgraded and refactored Sanitizing. Much less crap should get through now!
Conflicts:
app/assets/javascripts/discourse/components/syntax_highlighting.js
|
2013-10-15 10:53:11 -04:00 |
|
Robin Ward
|
af931f0444
|
Reverting the Sanitizer commit in case we have to do something urgent
before we deploy it early next week. It's in the branch `sanitizer` for
now.
This reverts commit 9e93d8ed52.
|
2013-10-11 16:44:26 -04:00 |
|
Robin Ward
|
9e93d8ed52
|
Upgraded and refactored Sanitizing. Much less crap should get through now!
Conflicts:
app/assets/javascripts/discourse/components/syntax_highlighting.js
|
2013-10-11 16:25:40 -04:00 |
|
Robin Ward
|
9e815dbef9
|
FIX: Blockquote issue
|
2013-10-01 16:45:45 -04:00 |
|
Robin Ward
|
37304b7eba
|
FIX: Too many new lines in long quotes
|
2013-09-27 15:08:56 -04:00 |
|
Robin Ward
|
84a8a358c3
|
Trivial: Rename dialect action to block quotes rather than simple quotes
|
2013-09-09 14:11:56 -04:00 |
|
Robin Ward
|
49910b860b
|
FIX: Regression that removed the ability to quote code
|
2013-09-09 13:20:03 -04:00 |
|
Robin Ward
|
a9f3489237
|
FIX: Don't onebox links with labels unless the labels are the same as the URL
|
2013-09-06 16:47:26 -04:00 |
|
Robin Ward
|
63be950e5f
|
FIX: Quotes inside a list
|
2013-09-05 17:04:01 -04:00 |
|
Robin Ward
|
63f2187d72
|
FIX: Don't do intraword italics when prefixed by a forward slash
|
2013-08-30 10:56:41 -04:00 |
|
Robin Ward
|
380a6c9e9d
|
FIX: Blockquotes prefixed by spaces
|
2013-08-29 15:18:27 -04:00 |
|
Robin Ward
|
c99cf64d70
|
FIX: Quoting within code blocks.
|
2013-08-29 14:42:31 -04:00 |
|
Robin Ward
|
45b9f8048a
|
Documentation update to dialect
|
2013-08-29 13:59:41 -04:00 |
|
Robin Ward
|
eb5830f3b0
|
FIX: Make getURL available to plugins while they are starting up in a similar load order
to the client app.
|
2013-08-29 13:11:12 -04:00 |
|
Robin Ward
|
3cec95a2c3
|
Better API for parsing out blocks in the parser.
|
2013-08-29 11:47:44 -04:00 |
|