-
Notifications
You must be signed in to change notification settings - Fork 918
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug] 在编辑器里面写style标签并且添加样式,会污染外部全局样式 #812
Comments
这个是有xss白名单过滤的吧,参考一下主目录README.md?
要避免直接渲染编辑区的html标签,props栏的html手动设为false即可,更细的调整则在xssOptions中进行。 |
是的,确实有xss白名单过滤,谢谢大佬提醒; |
“不影响外部样式” 这句话我不太理解。按MDN<style>的说法,一个页面下可以包含多个 上述观点如表达不妥敬请指正。 |
最终我手动修改了 编辑器的DOM,去掉预览区,用iframe替换,彻底解决了样式污染的问题 // 去掉预览 // 使用iframe实现预览 |
🐛 Bug Report
假如用户输入:
<style> html { display: none } </style>直接就把整个页面整没了,不知道有没有方法实现样式隔离
The text was updated successfully, but these errors were encountered: