Skip to content

v2.24.1

Latest

Choose a tag to compare

@redimp redimp released this 08 Sep 20:30

Compare with v2.24.0

Security Fixes

  • Check style attributes for dangerous CSS in clean_html: url() targets are held to the same protocol allowlist as href and src, and expression(), behavior:, -moz-binding: and @import are rejected, decoding entities, CSS escapes and comments first (488a8e7).

Bug Fixes

  • Render HTML entities like · in text again by passing entities through while html tags stay guarded by clean_html (e8a390b).
  • Fall back to a hidden textarea and document.execCommand("copy") when copying a code block over plain HTTP, where navigator.clipboard is unavailable, see #562 (5c75701).
  • Preserve unicode in uploaded filenames with a NFKC-normalized sanitize_filename(), aligning filename handling for pages and attachments, see #560 (b937bf2).
  • Don't indent empty lines when tab-indenting a selection in the editor, see #566 (b92df95).
  • Preserve blank lines inside indented code blocks, see #566 (d09b635).
  • Prevent MathJax from typesetting the editor source, see #564 (131a72e).