ChatMessagesHandling: Strip HTML of incoming messages.

This commit is contained in:
lain 2020-04-16 17:50:24 +02:00
commit e983f70884
2 changed files with 5 additions and 0 deletions

View file

@ -56,7 +56,9 @@ defmodule Pleroma.Web.ActivityPub.Transmogrifier.ChatMessageTest do
assert activity.recipients == [recipient.ap_id, author.ap_id]
%Object{} = object = Object.get_by_ap_id(activity.data["object"])
assert object
assert object.data["content"] == "You expected a cute girl? Too bad. alert('XSS')"
end
end
end