Ignore any <iframe> or <script> added

Created on 28 April 2023, about 1 year ago
Updated 8 November 2023, 8 months ago

Problem/Motivation

Steps to reproduce

If allowed, on the CKeditor or any other text paragraph component, or any other text field, add an iframe including or script code, that we just paste the raw value to show an embed (not recommended, but in some cases, for trusted providers, this can be ok - if controlled and checked on the backend, etc.) This will make the node_read_time module stop counting words, hence the estimated read time is not accurate.

Proposed resolution

Make sure script and iframe tags and nested elements are stripped.

Remaining tasks

Review and test.

🐛 Bug report
Status

Fixed

Version

1.11

Component

Code

Created by

🇬🇧United Kingdom andreastkdf

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.69.0 2024