github / github/markup

Revisiting Color in Markup

未关闭
#2,054 8 条评论 8 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Ruby
星标
6k
派生
3.4k
PR 合并指标
30 天内没有已合并 PR

描述

> Changes to the sanitize (step 2):
>
> ```
> color_transformer = lambda do |env|
> node = env[:node]
>
> # Only process element nodes with a style attribute
> return unless node.type == Nokogiri::XML::Node::ELEMENT_NODE
> return unless node['style']
>
> # Parse each declaration
> allowed_declarations = node['style'].split(';').filter_map do |declaration|
> property, value = declaration.split(':').map(&:strip)
> next unless property == 'color'
>
> # Allow only:
> # - Named colors: red, blue, darkslategray, etc. OR NOT?
> # - Hex colors: #fff, #ff6600
> # - RGB: rgb(0, 128, 255)
> # - HSL: hsl(120, 100%, 50%)
> valid_color = value.match?(
> /\A(
> \#([0-9a-fA-F]{3}|[0-9a-fA-F]{6}) | # hex
> rgb\(\s*\d{1,3}\s*,\s*\d{1,3}\s*,\s*\d{1,3}\s*\) | # rgb()
> hsl\(\s*\d{1,3}\s*,\s*\d{1,3}%\s*,\s*\d{1,3}%\s*\) | # hsl()
> [a-zA-Z]{2,50} # named color
> )\z/x
> )
>
> "color: #{value}" if valid_color
> end
>
> if allowed_declarations&.any?
> node['style'] = allowed_declarations.join('; ')
> else
> node.remove_attribute('style')
> end
> end
>
> ```
>
> --- THEN ADD THIS TO THE SANITIZE CONFIG ---
>
> ```
> config = {
> elements: ['p', 'span', 'em', 'strong'],
> attributes: {
> :all => ['style']
> },
> css: {
> properties: ['color']
> },
> transformers: [color_transformer]
> }
>
> Sanitize.fragment(html, config)
> ```

_Originally posted by @perlygatekeeper in [#1440](https://github.com/github/markup/issues/1440#issuecomment-4314431057)_

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。