diff doc/security.txt @ 6284:3f7538316724

issue2551099 - disable processing of data url's in markdown. Display as plain text. Added 'data' to templating.py _disable_url_schemes array. User should be able to re-enable it by changing the array from the tracker's interfaces.py. Markdown tests failed before the change to _disable_url_schemes. Also add second separate data test for ReST and plain text processing. data url's look like they are already ignored in these proess streams.
author John Rouillard <rouilj@ieee.org>
date Sat, 31 Oct 2020 15:43:53 -0400
parents 8ee41c7372e7
children ffe29ee47c47
line wrap: on
line diff

Roundup Issue Tracker: http://roundup-tracker.org/