refac/sec: sanitize note pdf download
This commit is contained in:
@@ -1,3 +1,5 @@
|
|||||||
|
import DOMPurify from 'dompurify';
|
||||||
|
|
||||||
export const downloadPdf = async (note) => {
|
export const downloadPdf = async (note) => {
|
||||||
const [{ default: jsPDF }, { default: html2canvas }] = await Promise.all([
|
const [{ default: jsPDF }, { default: html2canvas }] = await Promise.all([
|
||||||
import('jspdf'),
|
import('jspdf'),
|
||||||
@@ -9,7 +11,7 @@ export const downloadPdf = async (note) => {
|
|||||||
const virtualHeight = 1400; // Fixed height (adjust as needed)
|
const virtualHeight = 1400; // Fixed height (adjust as needed)
|
||||||
|
|
||||||
// STEP 1. Get a DOM node to render
|
// STEP 1. Get a DOM node to render
|
||||||
const html = note.data?.content?.html ?? '';
|
const html = DOMPurify.sanitize(note.data?.content?.html ?? '');
|
||||||
const isDarkMode = document.documentElement.classList.contains('dark');
|
const isDarkMode = document.documentElement.classList.contains('dark');
|
||||||
|
|
||||||
let node;
|
let node;
|
||||||
|
|||||||
Reference in New Issue
Block a user