Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Gist embed allowing unsafe html #7883

Merged
merged 1 commit into from
Apr 12, 2024
Merged

fix: Gist embed allowing unsafe html #7883

merged 1 commit into from
Apr 12, 2024

Conversation

dwelle
Copy link
Member

@dwelle dwelle commented Apr 12, 2024

No description provided.

Copy link

vercel bot commented Apr 12, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated (UTC)
excalidraw ✅ Ready (Inspect) Visit Preview Apr 12, 2024 10:53am
excalidraw-package-example ✅ Ready (Inspect) Visit Preview Apr 12, 2024 10:53am
excalidraw-package-example-with-nextjs ✅ Ready (Inspect) Visit Preview Apr 12, 2024 10:53am
1 Ignored Deployment
Name Status Preview Updated (UTC)
docs ⬜️ Ignored (Inspect) Apr 12, 2024 10:53am

Copy link

Coverage Report

Status Category Percentage Covered / Total
🔴 Lines 64.4% (🎯 70%) 48428 / 75192
🔴 Statements 64.4% (🎯 70%) 48428 / 75192
🔴 Functions 65.01% (🎯 68%) 1459 / 2244
🟢 Branches 80.17% (🎯 70%) 5828 / 7269
File Coverage
File Stmts % Branch % Funcs % Lines Uncovered Lines
Changed Files
packages/excalidraw/components/App.tsx 69.07% 75.75% 67.87% 69.07% 473-474, 580-589, 684-685, 703-704, 724-784, 787-793, 796-799, 802-878, 881-900, 903-908, 916-926, 928-929, 934-935, 939-941, 955, 962-1223, 1283-1284, 1295-1296, 1324-1326, 1336-1381, 1407, 1417, 1424-1427, 1436-1440, 1471-1472, 1556-1566, 1571-1586, 1590-1637, 1708-1713, 1742-1747, 1750-1780, 1788-1813, 1816-1825, 1828-1940, 1943-1951, 1960-1973, 1976-2002, 2005-2076, 2079-2119, 2165-2166, 2180-2181, 2218-2219, 2223-2224, 2240-2247, 2252-2265, 2271-2272, 2277-2285, 2287-2295, 2307, 2347-2348, 2370-2371, 2378, 2439-2441, 2444-2449, 2454-2455, 2492-2500, 2505-2514, 2552-2553, 2636-2637, 2641, 2644-2645, 2653-2656, 2665-2678, 2684-2687, 2690, 2692-2693, 2700-2701, 2707-2708, 2711-2712, 2720-2721, 2724-2725, 2728-2731, 2742-2750, 2755-2756, 2805-2806, 2820-2826, 2832-2840, 2844-2852, 2856-2857, 2860-2893, 2896-2908, 2919-2920, 2931-2932, 2949-2953, 2957-2960, 2967-2969, 2987-2994, 2997, 2999-3004, 3008-3010, 3031-3032, 3039-3041, 3043-3066, 3092, 3098, 3154-3155, 3172-3174, 3196-3197, 3203-3206, 3212-3293, 3365-3366, 3425, 3435-3453, 3456-3462, 3465-3466, 3472-3485, 3571-3572, 3574-3575, 3580-3582, 3590-3591, 3614-3628, 3633-3652, 3675-3676, 3748, 3757-3758, 3760-3767, 3782-3786, 3797-3798, 3801-3805, 3807-3808, 3810-3813, 3838-3839, 3848-3850, 3852, 3930-3933, 3955-3957, 3967-3968, 3970-3990, 3993-3999, 4016-4019, 4025-4028, 4038-4045, 4049-4050, 4056, 4084-4088, 4092, 4097-4098, 4103-4107, 4135-4136, 4139-4140, 4143-4144, 4152-4156, 4161-4162, 4168-4178, 4183-4210, 4215-4226, 4293, 4319-4320, 4385-4390, 4490, 4516-4518, 4585-4586, 4601-4602, 4772-4773, 4776-4777, 4785, 4833-4837, 4888-4895, 4901-4967, 5011, 5060, 5087, 5094-5095, 5104-5107, 5138, 5186-5189, 5192-5198, 5200-5203, 5218-5227, 5230-5231, 5313-5314, 5317, 5319-5324, 5330-5332, 5334, 5343, 5365-5370, 5372-5375, 5379-5380, 5390-5490, 5494-5495, 5510-5511, 5544-5545, 5572-5573, 5606-5632, 5639-5640, 5662-5663, 5682, 5684-5727, 5732-5733, 5735-5736, 5752-5753, 5759-5760, 5764-5767, 5770-5771, 5786-5813, 5821-5822, 5826-5829, 5831-5835, 5853-5857, 5903-5908, 5910-5912, 5928, 5930-5943, 5968-5971, 6015, 6032-6033, 6035-6058, 6073-6074, 6185-6213, 6282-6286, 6310-6311, 6331-6332, 6426, 6432-6433, 6456-6475, 6490, 6618, 6640-6678, 6682-6732, 6747, 6756, 6790-6796, 6811-6813, 6955-6958, 6982-7013, 7026, 7028-7036, 7050, 7052-7060, 7067-7070, 7078-7083, 7110-7111, 7116-7118, 7121-7122, 7147-7148, 7179-7180, 7263-7264, 7313-7326, 7387-7390, 7416-7417, 7453-7454, 7467, 7485-7491, 7498-7501, 7524-7530, 7602, 7608, 7623-7630, 7633-7640, 7696, 7773-7774, 7795-7797, 7800, 7814-7838, 7941-7965, 7975-8014, 8027-8028, 8037-8044, 8058-8071, 8084-8089, 8143-8169, 8171-8172, 8246-8247, 8254, 8256-8292, 8321, 8382, 8407-8409, 8434-8439, 8441-8442, 8447-8449, 8452-8472, 8486-8487, 8493-8502, 8507, 8511-8515, 8524-8528, 8531-8536, 8540-8547, 8577, 8579-8583, 8585-8595, 8611-8613, 8624-8632, 8636-8680, 8683-8754, 8762, 8780-8787, 8789-8805, 8820-8842, 8861-8863, 8908-8909, 8939-8940, 8959, 9036-9040, 9042-9058, 9060-9064, 9076-9077, 9087-9103, 9121-9140, 9142-9143, 9164-9165, 9169-9170, 9180, 9182-9185, 9187-9188, 9228, 9249-9250, 9276, 9279, 9320, 9334-9342, 9359-9360, 9392-9395, 9484-9491, 9517-9518, 9559-9613, 9661-9662, 9671-9674, 9679-9680, 9701-9703, 9705-9709, 9747
packages/excalidraw/element/embeddable.ts 34.21% 23.07% 42.85% 34.21% 60-61, 64-189, 192-226, 234-253, 271-279, 289-290, 294-295, 298-299, 303-304, 314-315, 317-339
packages/excalidraw/element/types.ts 0% 0% 0% 0% 1-309
Generated in workflow #2262

@dwelle dwelle merged commit 0ae9b38 into master Apr 12, 2024
11 checks passed
@dwelle dwelle deleted the dwelle/fix-gist-embed branch April 12, 2024 10:57
dwelle added a commit that referenced this pull request Apr 12, 2024
dwelle added a commit that referenced this pull request Apr 12, 2024
wangshijun added a commit to wangshijun/excalidraw-blocklet that referenced this pull request May 22, 2024
patch release

* tag 'v0.17.5':
  v0.17.5
  fix: parse embeddable srcdoc urls strictly & escape attribute url html
  v0.17.4
  fix: Gist embed allowing unsafe html (excalidraw#7883)
  fix: keep customData when converting to ExcalidrawElement (excalidraw#7656)
  fix: umd build so it can be used in browser (excalidraw#7349)
  fix: disable caching bounds for arrow labels (excalidraw#7343)
  fix: bounds cached prematurely resulting in incorrectly rendered labels (excalidraw#7339)
  docs: upgrade to @excalidraw/excalidraw@0.17.0 (excalidraw#7285)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant