klen / klen/django_markdown

No Cross Site Scripting prevention

Open
#45 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
389
Forks
140
PR merge metrics
No merged PRs in 30d

Description

As far as I could see there is no way to protect myself from cross-site scripting with this extension, am I right? If so, the package documentation could at least need some warnings for users of this extension ...
##

---
Want to back this issue? **[Post a bounty on it!](https://www.bountysource.com/issues/8656835-no-cross-site-scripting-prevention?utm_campaign=plugin&utm_content=tracker%2F332251&utm_medium=issues&utm_source=github)** We accept bounties via [Bountysource](https://www.bountysource.com/?utm_campaign=plugin&utm_content=tracker%2F332251&utm_medium=issues&utm_source=github).

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue does not name a file, test, or entry point. First inspect the extension's handling of rendered Markdown and existing package documentation, then establish whether an XSS protection gap exists; done means documenting the relevant risk and user guidance if the concern is confirmed.

Written by the indexing model from the issue text.

Assessment

Tech stack
django, javascript
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.