diff options
author | 2022-05-26 11:37:13 +0200 | |
---|---|---|
committer | 2022-05-26 11:37:13 +0200 | |
commit | 5668ce1ec701ed12eb099020e8a322de08e6f810 (patch) | |
tree | f056890ae94f464176750be17b06292c5b9160d7 /internal/processing/account/update.go | |
parent | [security] Set SameSite to `strict` instead of browser default (#606) (diff) | |
download | gotosocial-5668ce1ec701ed12eb099020e8a322de08e6f810.tar.xz |
[bugfix] Fix HTML escaping in instance title (#607)
* move caption sanitization -> sanitize.go
* use sanitizeplaintext rather than removehtml
* rename sanitizecaption to sanitizeplaintext
* avoid removing html twice from statuses
* unexport remoteHTML
it's no longer used outside the text package so this
makes it less confusing
* test instance PATCH
Diffstat (limited to 'internal/processing/account/update.go')
-rw-r--r-- | internal/processing/account/update.go | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/internal/processing/account/update.go b/internal/processing/account/update.go index 3d6bbae2a..5fae6e73b 100644 --- a/internal/processing/account/update.go +++ b/internal/processing/account/update.go @@ -53,7 +53,7 @@ func (p *processor) Update(ctx context.Context, account *gtsmodel.Account, form if err := validate.DisplayName(*form.DisplayName); err != nil { return nil, err } - account.DisplayName = text.RemoveHTML(*form.DisplayName) + account.DisplayName = text.SanitizePlaintext(*form.DisplayName) } if form.Note != nil { |