From 04b3984dd12f30392d1a20b6f0da3997c73e6033 Mon Sep 17 00:00:00 2001 From: MAEDA Go Date: Fri, 9 Oct 2026 14:08:08 +0900 Subject: [PATCH 3/4] Allow the same CSS properties in the style attribute in CommonMark as in Textile --- .../wiki_formatting/sanitization_filter.rb | 17 ++++++----------- .../textile/sanitization_filter.rb | 6 ------ .../common_mark/formatter_test.rb | 2 +- .../common_mark/sanitization_filter_test.rb | 4 ++++ 4 files changed, 11 insertions(+), 18 deletions(-) diff --git a/lib/redmine/wiki_formatting/sanitization_filter.rb b/lib/redmine/wiki_formatting/sanitization_filter.rb index f280ffd24..091fc4cd8 100644 --- a/lib/redmine/wiki_formatting/sanitization_filter.rb +++ b/lib/redmine/wiki_formatting/sanitization_filter.rb @@ -38,6 +38,11 @@ module Redmine TABLE = 'table' TABLE_SECTIONS = Set.new(%w[thead tbody tfoot].freeze) + # Same properties as the ones accepted by RedCloth3::STYLES_RE + STYLE_PROPERTY_RE = /\A(color|(min-|max-)?(width|height)|border|background|padding|margin|font|text|float)(-[a-z]+)*\z/ + STYLE_PROPERTIES = + (Sanitize::Config::RELAXED[:css][:properties].grep(STYLE_PROPERTY_RE) + %w[line-height vertical-align]).freeze + # The main sanitization allowlist. Only these elements and attributes are # allowed through by default. ALLOWLIST = { @@ -109,17 +114,7 @@ module Redmine } ].freeze, :css => { - :properties => %w[ - color background-color - width min-width max-width - height min-height max-height - padding padding-left padding-right padding-top padding-bottom - margin margin-left margin-right margin-top margin-bottom - border border-left border-right border-top border-bottom border-radius border-style border-collapse border-spacing - font font-style font-variant font-weight font-stretch font-size line-height font-family - text-align text-decoration - float - ].freeze + :properties => STYLE_PROPERTIES } }.freeze diff --git a/lib/redmine/wiki_formatting/textile/sanitization_filter.rb b/lib/redmine/wiki_formatting/textile/sanitization_filter.rb index 0db5804f2..4e6fa37a4 100644 --- a/lib/redmine/wiki_formatting/textile/sanitization_filter.rb +++ b/lib/redmine/wiki_formatting/textile/sanitization_filter.rb @@ -25,11 +25,6 @@ module Redmine ALLOWED_CLASS_RE = /\A(wiki-class-\S+|external|email|footnote)\z/ ALLOWED_ID_RE = /\A(wiki-id-\S+|fn\d+)\z/ - # Same properties as the ones accepted by RedCloth3::STYLES_RE - STYLE_PROPERTY_RE = /\A(color|(min-|max-)?(width|height)|border|background|padding|margin|font|text|float)(-[a-z]+)*\z/ - STYLE_PROPERTIES = - (Sanitize::Config::RELAXED[:css][:properties].grep(STYLE_PROPERTY_RE) + %w[vertical-align]).freeze - private def default_allowlist @@ -37,7 +32,6 @@ module Redmine allowlist[:elements] += %w[font] allowlist[:attributes][:all] += %w[class id] allowlist[:attributes]['font'] = %w[face] - allowlist[:css][:properties] |= STYLE_PROPERTIES allowlist end diff --git a/test/unit/lib/redmine/wiki_formatting/common_mark/formatter_test.rb b/test/unit/lib/redmine/wiki_formatting/common_mark/formatter_test.rb index 973aba6e3..ff78bef5c 100644 --- a/test/unit/lib/redmine/wiki_formatting/common_mark/formatter_test.rb +++ b/test/unit/lib/redmine/wiki_formatting/common_mark/formatter_test.rb @@ -255,7 +255,7 @@ class Redmine::WikiFormatting::CommonMark::FormatterTest < Redmine::HelperTest end def test_should_support_html_tables - text = '
Cell
' + text = '
Cell
' assert_equal '
Cell
', to_html(text) end diff --git a/test/unit/lib/redmine/wiki_formatting/common_mark/sanitization_filter_test.rb b/test/unit/lib/redmine/wiki_formatting/common_mark/sanitization_filter_test.rb index 1bbb96630..f17911809 100644 --- a/test/unit/lib/redmine/wiki_formatting/common_mark/sanitization_filter_test.rb +++ b/test/unit/lib/redmine/wiki_formatting/common_mark/sanitization_filter_test.rb @@ -125,6 +125,10 @@ if Object.const_defined?(:Commonmarker) 'hello"', 'hello"' ], + [ + 'hello', + 'hello' + ], [ '', '' -- 2.55.0