mirror of
https://github.com/9001/copyparty.git
synced 2026-01-04 10:35:38 +10:00
by running dompurify after marked.parse if plugins are not enabled; adds no protection against the more practical approach of just putting a malicious <script> in an html file and uploading that, but one footgun less is one less footgun