|
14 | 14 | from kitsune.sumo.sanitize import clean, linkify |
15 | 15 | from kitsune.sumo.urlresolvers import reverse |
16 | 16 |
|
17 | | -ALLOWED_ATTRIBUTES = { |
| 17 | +BASE_ALLOWED_ATTRIBUTES = { |
18 | 18 | "a": ["href", "title", "class", "rel", "data-mozilla-ui-reset", "data-mozilla-ui-preferences"], |
19 | | - "div": ["id", "class", "style", "data-for", "title", "data-target", "data-modal"], |
20 | | - "h1": ["id"], |
21 | | - "h2": ["id"], |
22 | | - "h3": ["id"], |
23 | | - "h4": ["id"], |
24 | | - "h5": ["id"], |
25 | | - "h6": ["id"], |
| 19 | + "div": ["class", "style", "data-for", "title"], |
26 | 20 | "li": ["class"], |
27 | 21 | "span": ["class", "data-for"], |
28 | 22 | "img": ["class", "src", "data-original-src", "alt", "title", "height", "width", "style"], |
|
37 | 31 | ], |
38 | 32 | "source": ["src", "type"], |
39 | 33 | } |
| 34 | + |
| 35 | +ALLOWED_ATTRIBUTES = { |
| 36 | + **BASE_ALLOWED_ATTRIBUTES, |
| 37 | + "div": BASE_ALLOWED_ATTRIBUTES["div"] + ["id", "data-target", "data-modal"], |
| 38 | + "h1": ["id"], |
| 39 | + "h2": ["id"], |
| 40 | + "h3": ["id"], |
| 41 | + "h4": ["id"], |
| 42 | + "h5": ["id"], |
| 43 | + "h6": ["id"], |
| 44 | +} |
40 | 45 | ALLOWED_STYLES = ["vertical-align"] |
41 | 46 | IMAGE_PARAMS = ["alt", "align", "caption", "valign", "frame", "page", "link", "width", "height"] |
42 | 47 | IMAGE_PARAM_VALUES = { |
|
0 commit comments