1
0
Fork 0
mirror of https://github.com/plankanban/planka.git synced 2025-07-18 20:59:44 +02:00

fix: Prevent tabnabbing in markdown

This commit is contained in:
Maksim Eltyshev 2022-08-30 13:47:50 +02:00
parent d355cd9d57
commit f8720b8020

View file

@ -6,6 +6,8 @@ import remarkBreaks from 'remark-breaks';
import './Markdown.module.scss'; // FIXME: import as styles?
const ABSOLUTE_URL_REGEX = /^(?:https?:)?\/\//i;
const Markdown = React.memo(({ linkStopPropagation, ...props }) => {
const handleLinkClick = useCallback((event) => {
event.stopPropagation();
@ -16,25 +18,30 @@ const Markdown = React.memo(({ linkStopPropagation, ...props }) => {
jsx-a11y/click-events-have-key-events,
jsx-a11y/no-static-element-interactions,
react/jsx-props-no-spreading */
({ node, ...linkProps }) => <a {...linkProps} onClick={handleLinkClick} />,
({ node, ...linkProps }) => (
<a
{...linkProps}
rel={
ABSOLUTE_URL_REGEX.test(linkProps.href) && linkProps.target === '_blank'
? 'noreferrer'
: undefined
}
onClick={linkStopPropagation ? handleLinkClick : undefined}
/>
),
/* eslint-enable jsx-a11y/anchor-has-content,
jsx-a11y/click-events-have-key-events,
jsx-a11y/no-static-element-interactions,
react/jsx-props-no-spreading */
[handleLinkClick],
[linkStopPropagation, handleLinkClick],
);
let components;
if (linkStopPropagation) {
components = {
a: linkRenderer,
};
}
return (
<ReactMarkdown
{...props} // eslint-disable-line react/jsx-props-no-spreading
components={components}
components={{
a: linkRenderer,
}}
remarkPlugins={[remarkGfm, remarkBreaks]}
className="markdown-body"
/>