Project

General

Profile

Feature #44585 » 0003-Allow-the-same-CSS-properties-in-the-style-attribute.patch

Go MAEDA, 2026-10-09 07:20

View differences:

lib/redmine/wiki_formatting/sanitization_filter.rb
38 38
      TABLE = 'table'
39 39
      TABLE_SECTIONS = Set.new(%w[thead tbody tfoot].freeze)
40 40

  
41
      # Same properties as the ones accepted by RedCloth3::STYLES_RE
42
      STYLE_PROPERTY_RE = /\A(color|(min-|max-)?(width|height)|border|background|padding|margin|font|text|float)(-[a-z]+)*\z/
43
      STYLE_PROPERTIES =
44
        (Sanitize::Config::RELAXED[:css][:properties].grep(STYLE_PROPERTY_RE) + %w[line-height vertical-align]).freeze
45

  
41 46
      # The main sanitization allowlist. Only these elements and attributes are
42 47
      # allowed through by default.
43 48
      ALLOWLIST = {
......
109 114
            }
110 115
          ].freeze,
111 116
          :css => {
112
            :properties => %w[
113
              color background-color
114
              width min-width max-width
115
              height min-height max-height
116
              padding padding-left padding-right padding-top padding-bottom
117
              margin margin-left margin-right margin-top margin-bottom
118
              border border-left border-right border-top border-bottom border-radius border-style border-collapse border-spacing
119
              font font-style font-variant font-weight font-stretch font-size line-height font-family
120
              text-align text-decoration
121
              float
122
            ].freeze
117
            :properties => STYLE_PROPERTIES
123 118
          }
124 119
      }.freeze
125 120

  
lib/redmine/wiki_formatting/textile/sanitization_filter.rb
25 25
        ALLOWED_CLASS_RE = /\A(wiki-class-\S+|external|email|footnote)\z/
26 26
        ALLOWED_ID_RE = /\A(wiki-id-\S+|fn\d+)\z/
27 27

  
28
        # Same properties as the ones accepted by RedCloth3::STYLES_RE
29
        STYLE_PROPERTY_RE = /\A(color|(min-|max-)?(width|height)|border|background|padding|margin|font|text|float)(-[a-z]+)*\z/
30
        STYLE_PROPERTIES =
31
          (Sanitize::Config::RELAXED[:css][:properties].grep(STYLE_PROPERTY_RE) + %w[vertical-align]).freeze
32

  
33 28
        private
34 29

  
35 30
        def default_allowlist
......
37 32
          allowlist[:elements] += %w[font]
38 33
          allowlist[:attributes][:all] += %w[class id]
39 34
          allowlist[:attributes]['font'] = %w[face]
40
          allowlist[:css][:properties] |= STYLE_PROPERTIES
41 35
          allowlist
42 36
        end
43 37

  
test/unit/lib/redmine/wiki_formatting/common_mark/formatter_test.rb
255 255
    end
256 256

  
257 257
    def test_should_support_html_tables
258
      text = '<table style="background: red"><tr><td>Cell</td></tr></table>'
258
      text = '<table style="position: fixed"><tr><td>Cell</td></tr></table>'
259 259
      assert_equal '<table><tbody><tr><td>Cell</td></tr></tbody></table>', to_html(text)
260 260
    end
261 261

  
test/unit/lib/redmine/wiki_formatting/common_mark/sanitization_filter_test.rb
125 125
        '<span style="color: #333; background: url(\'https://example.com/evil.svg\')">hello</span>"',
126 126
        '<span style="color: #333; ">hello</span>"'
127 127
      ],
128
      [
129
        '<span style="background: #fdd; vertical-align: top; border-top-left-radius: 4px;">hello</span>',
130
        '<span style="background: #fdd; vertical-align: top; border-top-left-radius: 4px;">hello</span>'
131
      ],
128 132
      [
129 133
        '<img src="photo.jpg" style="min-width: 100px; max-width: 200px; min-height: 100px; max-height: 200px;">',
130 134
        '<img src="photo.jpg" style="min-width: 100px; max-width: 200px; min-height: 100px; max-height: 200px;">'
(3-3/3)