mirror of
https://github.com/9001/copyparty.git
synced 2026-10-01 14:05:48 +01:00
by running dompurify after marked.parse if plugins are not enabled; adds no protection against the more practical approach of just putting a malicious <script> in an html file and uploading that, but one footgun less is one less footgun