2019-07-30 16:40:59 +02:00
|
|
|
# Portions of this file are derived from Pleroma:
|
|
|
|
# Copyright © 2017-2019 Pleroma Authors <https://pleroma.social>
|
|
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
# Upstream: https://git.pleroma.social/pleroma/pleroma/blob/develop/lib/pleroma/html.ex
|
|
|
|
|
2020-01-22 02:14:42 +01:00
|
|
|
defmodule Mobilizon.Service.Formatter.DefaultScrubbler do
|
2019-07-30 16:40:59 +02:00
|
|
|
@moduledoc """
|
2020-01-22 02:14:42 +01:00
|
|
|
Custom strategy to filter HTML content.
|
2019-07-30 16:40:59 +02:00
|
|
|
"""
|
|
|
|
|
2020-01-22 02:14:42 +01:00
|
|
|
alias HtmlSanitizeEx.Scrubber.Meta
|
2019-07-30 16:40:59 +02:00
|
|
|
|
|
|
|
require HtmlSanitizeEx.Scrubber.Meta
|
2020-01-22 02:14:42 +01:00
|
|
|
|
2019-07-30 16:40:59 +02:00
|
|
|
# credo:disable-for-previous-line
|
|
|
|
# No idea how to fix this one…
|
|
|
|
|
|
|
|
Meta.remove_cdata_sections_before_scrub()
|
|
|
|
Meta.strip_comments()
|
|
|
|
|
|
|
|
Meta.allow_tag_with_uri_attributes("a", ["href", "data-user", "data-tag"], ["https", "http"])
|
|
|
|
|
|
|
|
Meta.allow_tag_with_this_attribute_values("a", "class", [
|
|
|
|
"hashtag",
|
|
|
|
"u-url",
|
|
|
|
"mention",
|
|
|
|
"u-url mention",
|
|
|
|
"mention u-url"
|
|
|
|
])
|
|
|
|
|
|
|
|
Meta.allow_tag_with_this_attribute_values("a", "rel", [
|
|
|
|
"tag",
|
|
|
|
"nofollow",
|
|
|
|
"noopener",
|
2019-12-03 11:29:51 +01:00
|
|
|
"noreferrer",
|
|
|
|
"ugc"
|
2019-07-30 16:40:59 +02:00
|
|
|
])
|
|
|
|
|
|
|
|
Meta.allow_tag_with_these_attributes("a", ["name", "title"])
|
|
|
|
|
|
|
|
Meta.allow_tag_with_these_attributes("abbr", ["title"])
|
|
|
|
|
|
|
|
Meta.allow_tag_with_these_attributes("b", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("blockquote", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("br", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("code", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("del", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("em", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("i", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("li", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("ol", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("p", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("pre", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("strong", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("u", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("ul", [])
|
2019-10-10 11:05:53 +02:00
|
|
|
Meta.allow_tag_with_these_attributes("img", ["src", "alt"])
|
2019-07-30 16:40:59 +02:00
|
|
|
|
2019-12-03 11:29:51 +01:00
|
|
|
Meta.allow_tag_with_this_attribute_values("span", "class", ["h-card", "mention"])
|
|
|
|
Meta.allow_tag_with_these_attributes("span", ["data-user"])
|
2019-07-30 16:40:59 +02:00
|
|
|
|
|
|
|
Meta.allow_tag_with_these_attributes("h1", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("h2", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("h3", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("h4", [])
|
|
|
|
Meta.allow_tag_with_these_attributes("h5", [])
|
|
|
|
|
|
|
|
Meta.strip_everything_not_covered()
|
|
|
|
end
|