Prevent remote image injection with /img/emoji/ in url (#1245)
* test remote img blocking with /img/emoji/ in url * fix emoji filter prevent injection of remote img with /img/emoji in url
This commit is contained in:
@@ -33,7 +33,7 @@ blah blah blah
|
||||
|
||||
// Test to make sure we block remote images in chat messages.
|
||||
func TestBlockRemoteImages(t *testing.T) {
|
||||
messageContent := `<img src="https://via.placeholder.com/350x150"> test `
|
||||
messageContent := `<img src="https://via.placeholder.com/img/emoji/350x150"> test `
|
||||
expected := `<p> test </p>`
|
||||
result := events.RenderAndSanitize(messageContent)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user