api.go 760 B

123456789101112131415161718192021222324252627282930313233343536
  1. // Copyright 2020 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package app
  5. import (
  6. "net/http"
  7. "github.com/microcosm-cc/bluemonday"
  8. "gopkg.in/macaron.v1"
  9. "gogs.io/gogs/internal/context"
  10. )
  11. func ipynbSanitizer() *bluemonday.Policy {
  12. p := bluemonday.UGCPolicy()
  13. p.AllowAttrs("class", "data-prompt-number").OnElements("div")
  14. p.AllowAttrs("class").OnElements("img")
  15. p.AllowURLSchemes("data")
  16. return p
  17. }
  18. func SanitizeIpynb() macaron.Handler {
  19. p := ipynbSanitizer()
  20. return func(c *context.Context) {
  21. html, err := c.Req.Body().String()
  22. if err != nil {
  23. c.Error(err, "read body")
  24. return
  25. }
  26. c.PlainText(http.StatusOK, p.Sanitize(html))
  27. }
  28. }