-
Notifications
You must be signed in to change notification settings - Fork 232
Description
Hi,
looks like there's issue with CSS font-family sanitization, when the input is first sanitized it adds quotes to font-families. When the sanitized content is sanitized again it removes some font-families and leaving blanks separated with commas, causing CSS font-family to be invalid.
Input to sanitize:
<span style="font-family:WordVisi_MSFontService, Algerian, Algerian_EmbeddedFont, Algerian_MSFontService, sans-serif;">TEXT</span>
Sanitize input (adding quotes to font-families and lower case):
<span style="font-family:'wordvisi_msfontservice' , 'algerian' , 'algerian_embeddedfont' , 'algerian_msfontservice' , sans-serif">TEXT</span>
Sanitize again (issue removing font-families and adding commas, causing invalid font-family tag):
<span style="font-family:, 'algerian' , , , sans-serif">TEXT</span>
The issue is caused if policy is configured like below:
new HtmlPolicyBuilder().allowStyling(CssSchema.DEFAULT)
Thanks,
Juraj