diff --git a/config/defaults.json b/config/defaults.json index 2c6f733953..7132a867c7 100644 --- a/config/defaults.json +++ b/config/defaults.json @@ -99,5 +99,6 @@ "usersWhitelist": false, "multiForum": false, "feedsLimit": 10, - "tweetText": "" + "tweetText": "", + "forceSafeImageURLs": true } diff --git a/lib/richtext/lib/xss-filter.js b/lib/richtext/lib/xss-filter.js index 30a5d2af61..c88ae0bfcb 100644 --- a/lib/richtext/lib/xss-filter.js +++ b/lib/richtext/lib/xss-filter.js @@ -1,7 +1,7 @@ var xss = require('xss'); var deepMixIn = require('mout/object/deepMixIn'); var videoUrlInspector = require('democracyos-video-url-inspector'); - +var config = require('lib/config'); module.exports = function xssFilter (opts) { var defaults = { @@ -49,7 +49,7 @@ module.exports = function xssFilter (opts) { value = xss.safeAttrValue(tag, name, value, cssFilter); // Remove protocol from srcs, to force https when needed - if ('src' === name && 'string' === typeof value) { + if (config.forceSafeImageURLs && 'src' === name && 'string' === typeof value) { value = value.replace(/^https?:\/\//, '//'); }