You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Sanitize custom menu icons through clean_html() with the renderer's HTML allowlist, so allowlisted tags are no longer stripped from the sidebar icons, see #557 (a2a09bf, 96bd485 by @deseven). Thanks to @strangerinusall for reaching out about this issue.
Block entity-encoded protocols in clean_html() by normalizing attribute values (unescape, drop control characters and whitespace, lowercase) before the protocol check, and extend the checked attributes to action, formaction, data, background and xlink:href. Thanks to @sywinksvg for reaching out (d6e25dd).
Features
Add the {{include}} transclusion embedding to include a whole page or a single section into another page, with section lookup by heading anchor (independent of case, spacing or heading level) and guards against include cycles, see #547 (ff4f205, d067695, 0ffadc5).
Bug Fixes
Fix broken WikiLink false positives in the housekeeping scan for Mermaid diagram nodes, fenced code blocks and inline code spans, see #550#556#561 (4e58077 by @agu2347, 2472cb6 by @agu2347, 4062eb8).
Allow single-line embeddings whose options contain a pipe (e.g. {{PageIndex|src=*}}) to render, by ordering the embedding block rule ahead of the table rules (9d97bd4).
Make View/Preview paths match: serve the editor via an ?edit query flag, see #555 (19dc33e).
Prevent blockquotes, fancy blocks, alerts, folded blocks and spoilers from rendering behind a floated infobox, see #559 (e04968d).