climu/openstudyroom

Users can add javascript code inside forum post

climu opened this issue · 0 comments

climu commented

This is potentially dangerous I think and we should prevent that.
We are using mistune to parse the markdown with a custom renderer in here.