Fix: XSS vulnerability in Ragflow's chat view (#10519)
### What problem does this PR solve? Fix: XSS vulnerability in Ragflow's chat view ### Type of change - [x] Bug Fix (non-breaking change which fixes an issue)
This commit is contained in:
parent
ff4239c7cf
commit
8c75803b70
3 changed files with 6 additions and 6 deletions
|
|
@ -54,8 +54,8 @@ function MarkdownContent({
|
|||
const { setDocumentIds, data: fileThumbnails } =
|
||||
useFetchDocumentThumbnailsByIds();
|
||||
const contentWithCursor = useMemo(() => {
|
||||
// let text = DOMPurify.sanitize(content);
|
||||
let text = content;
|
||||
let text = DOMPurify.sanitize(content);
|
||||
// let text = content;
|
||||
if (text === '') {
|
||||
text = t('chat.searching');
|
||||
}
|
||||
|
|
|
|||
|
|
@ -48,8 +48,8 @@ const MarkdownContent = ({
|
|||
const { setDocumentIds, data: fileThumbnails } =
|
||||
useFetchDocumentThumbnailsByIds();
|
||||
const contentWithCursor = useMemo(() => {
|
||||
// let text = DOMPurify.sanitize(content);
|
||||
let text = content;
|
||||
let text = DOMPurify.sanitize(content);
|
||||
// let text = content;
|
||||
if (text === '') {
|
||||
text = t('chat.searching');
|
||||
}
|
||||
|
|
|
|||
|
|
@ -64,8 +64,8 @@ const MarkdownContent = ({
|
|||
const { setDocumentIds, data: fileThumbnails } =
|
||||
useFetchDocumentThumbnailsByIds();
|
||||
const contentWithCursor = useMemo(() => {
|
||||
// let text = DOMPurify.sanitize(content);
|
||||
let text = content;
|
||||
let text = DOMPurify.sanitize(content);
|
||||
// let text = content;
|
||||
if (text === '') {
|
||||
text = t('chat.searching');
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue