diff options
Diffstat (limited to 'html.c')
| -rw-r--r-- | html.c | 5 |
1 files changed, 5 insertions, 0 deletions
| @@ -2242,6 +2242,11 @@ xs_html *html_entry(snac *user, xs_dict *msg, int read_only, | |||
| 2242 | if (content && xs_str_in(content, o_href) != -1) | 2242 | if (content && xs_str_in(content, o_href) != -1) |
| 2243 | continue; | 2243 | continue; |
| 2244 | 2244 | ||
| 2245 | /* drop silently any attachment that may include JavaScript */ | ||
| 2246 | if (strcmp(type, "image/svg+xml") == 0 || | ||
| 2247 | strcmp(type, "text/html") == 0) | ||
| 2248 | continue; | ||
| 2249 | |||
| 2245 | /* do this attachment include an icon? */ | 2250 | /* do this attachment include an icon? */ |
| 2246 | const xs_dict *icon = xs_dict_get(a, "icon"); | 2251 | const xs_dict *icon = xs_dict_get(a, "icon"); |
| 2247 | if (xs_type(icon) == XSTYPE_DICT) { | 2252 | if (xs_type(icon) == XSTYPE_DICT) { |