Revert "Fix 8166 html tag validation (#8176)" (#9374)

This reverts commit 9a5f4cc0ef.
This commit is contained in:
Saq Imtiaz
2025-10-29 22:01:03 +01:00
committed by GitHub
parent 9a5f4cc0ef
commit 7898cb8446
12 changed files with 47 additions and 67 deletions
+3 -1
View File
@@ -35,7 +35,9 @@ ButtonWidget.prototype.render = function(parent,nextSibling) {
this.computeAttributes();
this.execute();
// Create element
tag = $tw.utils.makeTagNameSafe(this.buttonTag,tag)
if(this.buttonTag && $tw.config.htmlUnsafeElements.indexOf(this.buttonTag) === -1) {
tag = this.buttonTag;
}
domNode = this.document.createElement(tag);
this.domNode = domNode;
// Assign classes
+4 -1
View File
@@ -35,7 +35,10 @@ DraggableWidget.prototype.render = function(parent,nextSibling) {
// Execute our logic
this.execute();
// Sanitise the specified tag
tag = $tw.utils.makeTagNameSafe(this.draggableTag,"div");
tag = this.draggableTag;
if($tw.config.htmlUnsafeElements.indexOf(tag) !== -1) {
tag = "div";
}
// Create our element
domNode = this.document.createElement(tag);
// Assign classes
+3 -1
View File
@@ -32,7 +32,9 @@ DroppableWidget.prototype.render = function(parent,nextSibling) {
// Compute attributes and execute state
this.computeAttributes();
this.execute();
tag = $tw.utils.makeTagNameSafe(this.droppableTag,tag);
if(this.droppableTag && $tw.config.htmlUnsafeElements.indexOf(this.droppableTag) === -1) {
tag = this.droppableTag;
}
// Create element and assign classes
domNode = this.document.createElement(tag);
this.domNode = domNode;
+8 -3
View File
@@ -26,10 +26,15 @@ Render this widget into the DOM
ElementWidget.prototype.render = function(parent,nextSibling) {
this.parentDomNode = parent;
this.computeAttributes();
// Eliminate blacklisted elements
// Neuter blacklisted elements
this.tag = this.parseTreeNode.tag;
// Sanitize tag name if needed according to Custom Web-Componenets spec
this.tag = $tw.utils.makeTagNameSafe(this.tag, "safe-" + this.tag);
if($tw.config.htmlUnsafeElements.indexOf(this.tag) !== -1) {
this.tag = "safe-" + this.tag;
}
// Restrict tag name to digits, letts and dashes
this.tag = this.tag.replace(/[^0-9a-zA-Z\-]/mg,"");
// Default to a span
this.tag = this.tag || "span";
// Adjust headings by the current base level
var headingLevel = ["h1","h2","h3","h4","h5","h6"].indexOf(this.tag);
if(headingLevel !== -1) {
+3 -1
View File
@@ -32,7 +32,9 @@ EventWidget.prototype.render = function(parent,nextSibling) {
this.execute();
// Create element
var tag = this.parseTreeNode.isBlock ? "div" : "span";
tag = $tw.utils.makeTagNameSafe(this.elementTag,tag)
if(this.elementTag && $tw.config.htmlUnsafeElements.indexOf(this.elementTag) === -1) {
tag = this.elementTag;
}
var domNode = this.document.createElement(tag);
this.domNode = domNode;
// Assign classes
+4 -2
View File
@@ -31,7 +31,9 @@ KeyboardWidget.prototype.render = function(parent,nextSibling) {
this.computeAttributes();
this.execute();
var tag = this.parseTreeNode.isBlock ? "div" : "span";
tag = $tw.utils.makeTagNameSafe(this.tag,tag);
if(this.tag && $tw.config.htmlUnsafeElements.indexOf(this.tag) === -1) {
tag = this.tag;
}
// Create element
var domNode = this.document.createElement(tag);
// Assign classes
@@ -48,7 +50,7 @@ KeyboardWidget.prototype.render = function(parent,nextSibling) {
};
KeyboardWidget.prototype.handleChangeEvent = function(event) {
if($tw.keyboardManager.handleKeydownEvent(event, {onlyPriority: true})) {
if ($tw.keyboardManager.handleKeydownEvent(event, {onlyPriority: true})) {
return true;
}
+3 -1
View File
@@ -62,7 +62,9 @@ LinkWidget.prototype.renderLink = function(parent,nextSibling) {
var self = this;
// Sanitise the specified tag
var tag = this.linkTag;
tag = $tw.utils.makeTagNameSafe(tag,"a");
if($tw.config.htmlUnsafeElements.indexOf(tag) !== -1) {
tag = "a";
}
// Create our element
var namespace = this.getVariable("namespace",{defaultValue: "http://www.w3.org/1999/xhtml"}),
domNode = this.document.createElementNS(namespace,tag);
+5 -3
View File
@@ -30,7 +30,9 @@ RevealWidget.prototype.render = function(parent,nextSibling) {
this.computeAttributes();
this.execute();
var tag = this.parseTreeNode.isBlock ? "div" : "span";
tag = $tw.utils.makeTagNameSafe(this.revealTag,tag);
if(this.revealTag && $tw.config.htmlUnsafeElements.indexOf(this.revealTag) === -1) {
tag = this.revealTag;
}
var domNode = this.document.createElement(tag);
this.domNode = domNode;
this.assignDomNodeClasses();
@@ -91,9 +93,9 @@ RevealWidget.prototype.positionPopup = function(domNode) {
left = Math.max(0,left);
top = Math.max(0,top);
}
if(this.popup.absolute) {
if (this.popup.absolute) {
// Traverse the offsetParent chain and correct the offset to make it relative to the parent node.
for(var offsetParentDomNode = domNode.offsetParent; offsetParentDomNode; offsetParentDomNode = offsetParentDomNode.offsetParent) {
for (var offsetParentDomNode = domNode.offsetParent; offsetParentDomNode; offsetParentDomNode = offsetParentDomNode.offsetParent) {
left -= offsetParentDomNode.offsetLeft;
top -= offsetParentDomNode.offsetTop;
}