Solo permitir URLs web al sanitizar

fixes #2382
This commit is contained in:
f 2021-08-11 10:25:05 -03:00
parent 312df05a84
commit 0bd8a2243e

View file

@ -56,7 +56,7 @@ class MetadataContent < MetadataTemplate
uri = URI element['src']
# No permitimos recursos externos
element.remove unless uri.hostname.end_with? Site.domain
element.remove unless uri.scheme == 'https' && uri.hostname.end_with?(Site.domain)
rescue URI::Error
element.remove
end