<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hedgedoc, branch cindy</title>
<subtitle>Hedgedoc with support for CindyScript</subtitle>
<id>https://stuebinm.eu/git/hedgedoc/atom/?h=cindy</id>
<link rel='self' href='https://stuebinm.eu/git/hedgedoc/atom/?h=cindy'/>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/'/>
<updated>2021-05-17T18:12:50Z</updated>
<entry>
<title>Add simple support for cindyjs</title>
<updated>2021-05-17T18:12:50Z</updated>
<author>
<name>stuebinm</name>
</author>
<published>2021-03-09T00:23:23Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=b0f98a43381486995b99ed79e0eabb3af149dbf3'/>
<id>urn:sha1:b0f98a43381486995b99ed79e0eabb3af149dbf3</id>
<content type='text'>
Notably, the error output (in case of compiler errors) is generated
by overwriting the builtin console.error-function, which is a horrible
idea for many reasons, but there isn't really any other way right now.
</content>
</entry>
<entry>
<title>Merge pull request #1267 from hedgedoc/release/1.8.2</title>
<updated>2021-05-11T19:41:11Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T19:41:11Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=8b374d8c1972db2b09126e8f9cc10384552abf29'/>
<id>urn:sha1:8b374d8c1972db2b09126e8f9cc10384552abf29</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Bump version to 1.8.2</title>
<updated>2021-05-11T19:28:10Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T19:09:03Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=32e31ac1e3751c47985269890580561cf452c270'/>
<id>urn:sha1:32e31ac1e3751c47985269890580561cf452c270</id>
<content type='text'>
Signed-off-by: David Mehren &lt;git@herrmehren.de&gt;
</content>
</entry>
<entry>
<title>Add release notes for 1.8.2</title>
<updated>2021-05-11T19:28:10Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T17:42:57Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=81d73b2db9e0d9bc938e242bb57bd45d948ce4f4'/>
<id>urn:sha1:81d73b2db9e0d9bc938e242bb57bd45d948ce4f4</id>
<content type='text'>
Signed-off-by: David Mehren &lt;git@herrmehren.de&gt;
</content>
</entry>
<entry>
<title>Merge pull request from GHSA-gjg7-4j2h-94fq</title>
<updated>2021-05-11T19:13:25Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T19:13:25Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=01dad5821ee28377ebe640c6c72c3e0bb0d51ea7'/>
<id>urn:sha1:01dad5821ee28377ebe640c6c72c3e0bb0d51ea7</id>
<content type='text'>
Fix XSS in Open Graph &amp; User metadata</content>
</entry>
<entry>
<title>Merge pull request #1259 from hedgedoc/renovate/master-lock-file-maintenance</title>
<updated>2021-05-11T17:42:43Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T17:42:43Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=4cc9b3abe5f4ee55764fbdb6602f8133e4d73e53'/>
<id>urn:sha1:4cc9b3abe5f4ee55764fbdb6602f8133e4d73e53</id>
<content type='text'>
Lock file maintenance (master)</content>
</entry>
<entry>
<title>Lock file maintenance</title>
<updated>2021-05-11T17:15:20Z</updated>
<author>
<name>Renovate Bot</name>
</author>
<published>2021-05-11T17:15:20Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=716808fa956d6a6345880382070114764f9d9608'/>
<id>urn:sha1:716808fa956d6a6345880382070114764f9d9608</id>
<content type='text'>
Signed-off-by: Renovate Bot &lt;bot@renovateapp.com&gt;
</content>
</entry>
<entry>
<title>Merge pull request #1263 from hedgedoc/renovate/master-mermaid-8.x</title>
<updated>2021-05-11T17:13:35Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-11T17:13:35Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=65bf66adc3305d93e538fe3c368b0c7368666505'/>
<id>urn:sha1:65bf66adc3305d93e538fe3c368b0c7368666505</id>
<content type='text'>
Update dependency mermaid to v8.10.1 (master)</content>
</entry>
<entry>
<title>Update dependency mermaid to v8.10.1</title>
<updated>2021-05-10T17:39:12Z</updated>
<author>
<name>Renovate Bot</name>
</author>
<published>2021-05-10T17:39:12Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=0b997b540ad646df74c323ca33a89c14989ae947'/>
<id>urn:sha1:0b997b540ad646df74c323ca33a89c14989ae947</id>
<content type='text'>
Signed-off-by: Renovate Bot &lt;bot@renovateapp.com&gt;
</content>
</entry>
<entry>
<title>Sanitize username and photo URL</title>
<updated>2021-05-09T17:28:44Z</updated>
<author>
<name>David Mehren</name>
</author>
<published>2021-05-09T13:35:06Z</published>
<link rel='alternate' type='text/html' href='https://stuebinm.eu/git/hedgedoc/commit/?id=f552b14e11761a73237b3b3834827dde151b8b28'/>
<id>urn:sha1:f552b14e11761a73237b3b3834827dde151b8b28</id>
<content type='text'>
HedgeDoc displays the username and user photo at various places
by rendering the respective variables into an `ejs` template.
As the values are user-provided or generated from user-provided data,
it may be possible to inject unwanted HTML.

This commit sanitizes the username and photo URL by passing them
through the `xss` library.

Co-authored-by: Christoph (Sheogorath) Kern &lt;sheogorath@shivering-isles.com&gt;
Signed-off-by: David Mehren &lt;git@herrmehren.de&gt;
</content>
</entry>
</feed>
