Skip to content

Commit 6fb990a

Browse files
authored
fix: treat col as a self-closing tag (#5447)
* fix: treat col as a self-closing tag
1 parent 4d478d9 commit 6fb990a

3 files changed

Lines changed: 18 additions & 1 deletion

File tree

‎.changeset/sixty-hats-kneel.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Fix invalid HTML output for <col> elements in sanitize-html (treat void elements correctly)

‎packages/sanitize-html/index.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -953,7 +953,7 @@ sanitizeHtml.defaults = {
953953
'alt'
954954
],
955955
// Lots of these won't come up by default because we don't allow them
956-
selfClosing: [ 'img', 'br', 'hr', 'area', 'base', 'basefont', 'input', 'link', 'meta' ],
956+
selfClosing: [ 'img', 'br', 'hr', 'area', 'base', 'basefont', 'input', 'link', 'meta', 'col' ],
957957
// URL schemes we permit
958958
allowedSchemes: [ 'http', 'https', 'ftp', 'mailto', 'tel' ],
959959
allowedSchemesByTag: {},

‎packages/sanitize-html/test/test.js‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,18 @@ describe('sanitizeHtml', function() {
2323
it('should pass through simple, well-formed markup', function() {
2424
assert.equal(sanitizeHtml('<div><p>Hello <b>there</b></p></div>'), '<div><p>Hello <b>there</b></p></div>');
2525
});
26+
it('should preserve col as a self closing tag', function() {
27+
assert.equal(
28+
sanitizeHtml(
29+
'<table><colgroup><col span="2"></colgroup></table>',
30+
{
31+
allowedTags: false,
32+
allowedAttributes: false
33+
}
34+
),
35+
'<table><colgroup><col span="2" /></colgroup></table>'
36+
);
37+
});
2638
it('should not pass through any text outside html tag boundary since html tag is found and option is ON', function() {
2739
assert.equal(sanitizeHtml('Text before html tag<html><div><p>Hello <b>there</b></p></div></html>Text after html tag!P�X��[<p>paragraph after closing html</p>', {
2840
enforceHtmlBoundary: true

0 commit comments

Comments
 (0)