浏览代码

fix: secure html module removes target attribute from links (#2012)

Regev Brody 5 年之前
父节点
当前提交
037822b994
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      server/modules/rendering/html-security/renderer.js

+ 1 - 1
server/modules/rendering/html-security/renderer.js

@@ -7,7 +7,7 @@ module.exports = {
       const window = new JSDOM('').window
       const DOMPurify = createDOMPurify(window)
 
-      const allowedAttrs = ['v-pre', 'v-slot:tabs', 'v-slot:content']
+      const allowedAttrs = ['v-pre', 'v-slot:tabs', 'v-slot:content', 'target']
       const allowedTags = ['tabset', 'template']
 
       if (config.allowIFrames) {