Skip to content

Commit 77887b0

Browse files
fix: wrap markdown_styles list in CSSSanitizer for bleach.clean() (#14479)
The css_sanitizer parameter expects a CSSSanitizer instance, not a plain list. Co-authored-by: Matt Tesauro <mtesauro@gmail.com>
1 parent a58f164 commit 77887b0

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

dojo/templatetags/display_tags.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ def markdown_render(value):
9191
"markdown.extensions.fenced_code",
9292
"markdown.extensions.toc",
9393
"markdown.extensions.tables"])
94-
return mark_safe(bleach.clean(markdown_text, tags=markdown_tags, attributes=markdown_attrs, css_sanitizer=markdown_styles))
94+
return mark_safe(bleach.clean(markdown_text, tags=markdown_tags, attributes=markdown_attrs, css_sanitizer=CSSSanitizer(allowed_css_properties=markdown_styles)))
9595
return None
9696

9797

0 commit comments

Comments
 (0)