From 01e53c3d27458297dc1c6b1792ebec510cc2ec9e Mon Sep 17 00:00:00 2001 From: Harvey Kandola Date: Mon, 12 Sep 2022 12:35:40 -0400 Subject: [PATCH] Fix sanitization of document title --- domain/document/endpoint.go | 5 ++--- domain/space/endpoint.go | 3 +-- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/domain/document/endpoint.go b/domain/document/endpoint.go index 2ee2d56f..dc960550 100644 --- a/domain/document/endpoint.go +++ b/domain/document/endpoint.go @@ -43,7 +43,6 @@ import ( "github.com/documize/community/model/space" "github.com/documize/community/model/user" "github.com/documize/community/model/workflow" - "github.com/microcosm-cc/bluemonday" ) // Handler contains the runtime information such as logging and database. @@ -271,8 +270,8 @@ func (h *Handler) Update(w http.ResponseWriter, r *http.Request) { } } - d.Name = bluemonday.StrictPolicy().Sanitize(d.Name) - d.Excerpt = bluemonday.StrictPolicy().Sanitize(d.Excerpt) + // d.Name = bluemonday.StrictPolicy().Sanitize(d.Name) + // d.Excerpt = bluemonday.StrictPolicy().Sanitize(d.Excerpt) err = h.Store.Document.Update(ctx, d) if err != nil { diff --git a/domain/space/endpoint.go b/domain/space/endpoint.go index 38344745..509c539c 100644 --- a/domain/space/endpoint.go +++ b/domain/space/endpoint.go @@ -44,7 +44,6 @@ import ( "github.com/documize/community/model/space" "github.com/documize/community/model/user" wf "github.com/documize/community/model/workflow" - "github.com/microcosm-cc/bluemonday" uuid "github.com/nu7hatch/gouuid" ) @@ -100,7 +99,7 @@ func (h *Handler) Add(w http.ResponseWriter, r *http.Request) { var sp space.Space sp.Name = model.Name - sp.Description = bluemonday.StrictPolicy().Sanitize(model.Description) + // sp.Description = bluemonday.StrictPolicy().Sanitize(model.Description) sp.Icon = model.Icon sp.LabelID = model.LabelID