mirror of
				https://github.com/discourse/discourse.git
				synced 2025-02-25 18:55:32 -06:00 
			
		
		
		
	Revert "Revert "Merge branch 'master' of https://github.com/discourse/discourse""
This reverts commit20780a1eee. * SECURITY: re-adds accidentally reverted commit:03d26cd6: ensure embed_url contains valid http(s) uri * when the merge commite62a85cfwas reverted, git chose the2660c2e2parent to land on instead of the03d26cd6parent (which contains security fixes)
This commit is contained in:
		@@ -109,6 +109,8 @@ class TopicEmbed < ActiveRecord::Base
 | 
			
		||||
 | 
			
		||||
    url = UrlHelper.escape_uri(url)
 | 
			
		||||
    original_uri = URI.parse(url)
 | 
			
		||||
    raise URI::InvalidURIError unless original_uri.is_a?(URI::HTTP)
 | 
			
		||||
 | 
			
		||||
    opts = {
 | 
			
		||||
      tags: %w[div p code pre h1 h2 h3 b em i strong a img ul li ol blockquote],
 | 
			
		||||
      attributes: %w[href src class],
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user