Skip to content

Conversation

@visualjeff
Copy link

Changes:

  • Inserted a local function SanitizeHtml.
  • Modified processEntry function to apply SanitizeHTML against any text content coming from contentstack.

Tested in our Gatsby site using a test stack we have on contentstack and it seems to work fine.

Anyway, it's just a suggestion.

@visualjeff
Copy link
Author

I guess one could add a config setting to enable (on or off) for a HTML Sanitize feature? Having marketing and business people pasting in HTML into our CMS is a risk for our organization we'd like to mitigate.

@psykzz
Copy link

psykzz commented May 13, 2021

I would like to +1 to having the toggle, our use case includes having HTML fields and would like to ensure that continues to work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants