Skip to content

Harden OG HTML and markdown rendering#956

Open
MaxGhenis wants to merge 1 commit intomainfrom
codex/harden-og-and-markdown-xss
Open

Harden OG HTML and markdown rendering#956
MaxGhenis wants to merge 1 commit intomainfrom
codex/harden-og-and-markdown-xss

Conversation

@MaxGhenis
Copy link
Copy Markdown
Contributor

Summary

  • escape reflected OG URL/image values before embedding them in generated HTML
  • stop rendering raw HTML in markdown formatters and reject unsafe inline link schemes
  • add regression tests for reflected OG content, raw HTML markdown, and javascript footnote links

Closes #948
Closes #949
Closes #950

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 13, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
policyengine-app-v2 Ready Ready Preview, Comment Apr 13, 2026 10:39am
policyengine-calculator Ready Ready Preview, Comment Apr 13, 2026 10:39am
policyengine-calculator-next Ready Ready Preview, Comment Apr 13, 2026 10:39am
policyengine-website Ready Ready Preview, Comment Apr 13, 2026 10:39am

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant