We want to implement a "safe mode" in a Markdown parser called Parsedown. We have a MarkupEscaped option that disables HTML, but this is not enough. In order to be safe, the parser needs to sanitise user generated attribute values.
These are the:
hrefandtitleattributes ofatags.srcandtitleattributes ofimgtags.
How should we go about it?
Aucun commentaire:
Enregistrer un commentaire