docsifyjs / docsifyjs/docsify

`<script>` in the md file fetched from the basePath is not executed

Abierto
#1,659 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
JavaScript
Estrellas
31.5k
Forks
5.8k
Merge medio
9 d 8 h
PR fusionados (30 d)
2

Descripción

## Bug Report
`// my script` in md file from `basePath` is not executed.

#### Steps to reproduce
- Provide the `basePath` as a full url with a domain different from the domain of `index.html`.
- open url of `index.html` with your browser.
- When you fetch the md files from `basePath`, you can check that the script in the md file cannot be executed.

#### What is current behaviour
In this case, the value of `isRemoteUrl` is determined to be true, so the code is sanitized by the code below.

https://github.com/docsifyjs/docsify/blob/c3cdadc37137edcd9e219359973902d2fc8b66ff/src/core/render/index.js#L332-L334

#### What is the expected behaviour
`basePath` is a value that can be entered only with the authority of the document site administrator, and the basePath server can also be considered owned by the administrator, so the `isRemoteUrl` value should be `false`.

#### Other relevant information

<!-- (Update "[ ]" to "[x]" to check a box) -->
- [ ] Bug does still occur when all/other plugins are disabled?

- Your OS: macOS 11
- Node.js version:
- npm/yarn version:
- Browser version:
- Docsify version: 4.12.1
- Docsify plugins:

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.