generated from graasp/graasp-repo
-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Description
This does not look safe, as discussed we should investigate how to "safely" render that HTML. The best would be to sandbox it in an iframe to at least not have the potential scripts be running on the main page and thus exposing us to an attack.
Even better would be to only support certain links with their embed and generate the embed content as a component directly.
Originally posted by @spaenleh in #1091 (comment)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels