Relative URIs are considered safe
Darren Coxall darren.coxall@simplybusiness.co.uk
Mon, 09 Dec 2013 14:41:37 +0000
1 files changed,
1 insertions(+),
1 deletions(-)
jump to
M
inline.go
→
inline.go
@@ -718,7 +718,7 @@
return linkEnd - rewind } -var validUris = [][]byte{[]byte("http://"), []byte("https://"), []byte("ftp://"), []byte("mailto://")} +var validUris = [][]byte{[]byte("http://"), []byte("https://"), []byte("ftp://"), []byte("mailto://"), []byte("/")} func isSafeLink(link []byte) bool { for _, prefix := range validUris {