fix: xss处理后无class属性

This commit is contained in:
wangruidong
2024-04-11 15:47:26 +08:00
committed by w940853815
parent f409abbf79
commit 1dfdfe3932

View File

@@ -18,6 +18,7 @@ const options = {
if (['src', 'href'].indexOf(name) !== -1) { if (['src', 'href'].indexOf(name) !== -1) {
return name + '=' + value.replace('javascript:', 'java:').replace('data:', 'dt:') return name + '=' + value.replace('javascript:', 'java:').replace('data:', 'dt:')
} }
return name + '="' + xss.escapeAttrValue(value) + '"'
} }
} }
const filter = new xss.FilterXSS(options) const filter = new xss.FilterXSS(options)