Commit Graph

2865 Commits

Author SHA1 Message Date
Yukai Huang f564a010fb
Bump cm to 5.57.7
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 11:21:22 +08:00
Yukai Huang f2912efd25
As vscode-markdownlint behavior
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:56 +08:00
Yukai Huang ad6f82c9f6
Dark mode linter menu
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:55 +08:00
Yukai Huang 0b9dd91822
Update cm deps
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:55 +08:00
Yukai Huang f07e3f10b6
Fix invalid range
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:54 +08:00
Yukai Huang 7caa272175
Provide linter autofixes
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:54 +08:00
Yukai Huang f946b5ba04
Ignore os for markdownlint-rule-helpers
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:54 +08:00
Yukai Huang cdb18a31fe
Update deps
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-03-12 10:45:53 +08:00
Giuseppe Lo Presti c9399f33d1 Support anonymous updates via API if allowAnonymousEdits is true
Signed-off-by: Giuseppe Lo Presti <giuseppe.lopresti@cern.ch>
2021-03-09 12:32:54 +01:00
Yukai Huang 7200506563
Merge pull request #1660 from hackmdio/bugfix/heroku-postgres-ssl
Enforce PG ssl require mode on heroku
2021-03-02 11:57:05 +08:00
Yukai Huang 1cdfbad458
Run bin/heroku in heroku-postbuild phase
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-02-28 11:23:52 +08:00
Yukai Huang 497abc8bca
Enforce PG ssl require mode
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-02-28 11:20:39 +08:00
Max Wu 181adbd08e
Update CONTRIBUTING.md
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-02-18 16:28:00 +08:00
Yukai Huang 0fb184c2d8
Merge branch 'master' into develop 2021-01-26 01:58:26 +08:00
Yukai Huang 452f9ac124
Merge pull request #1650 from hackmdio/bugfix/fix-reveal-markdown-stored-xss
Fix slide mode stored XSS
2021-01-25 16:50:23 +08:00
Yukai Huang 5b4c7ef4bb
Merge pull request #1651 from hackmdio/bugfix/fix-pdf-embed-freeze-on-safari-big-sur
fix: avoid insert embed tag on the main thread which cause Safari on Big Sur freezing
2021-01-25 15:00:57 +08:00
Yukai Huang 14e93fdb24
Merge pull request #1652 from hackmdio/bugfix/fix-vimeo-jsonp-callback
fix: vimeo won't show up due to the jsonp callback data unable be parsed with jQuery
2021-01-25 15:00:40 +08:00
Max Wu c1a1290717
Merge pull request #1653 from hackmdio/fix/feature-section-slide-mode-link-broken 2021-01-22 15:45:14 +08:00
Raccoon d74d30cc37
fix: feature section slide mode link broken
Signed-off-by: Raccoon <raccoon@hackmd.io>
2021-01-22 15:29:08 +08:00
Max Wu 2b9affbc08 fix: code style
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:35:16 +08:00
Max Wu 47bab4266b fix: vimeo won't show up due to the jsonp callback data unable be parsed with jQuery
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:35:16 +08:00
Max Wu 250dba3ffd fix: typo
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:23:45 +08:00
Max Wu a1e3768f98 fix: avoid insert embed tag on the main thread which cause Safari on Big Sur freezing
upgrade pdfobject to version 2.2.4

Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:23:45 +08:00
Max Wu c47f0f0c71 fix: remove reveal options of dependencies which allow import user defined resources [Security Issue]
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 13:24:48 +08:00
Max Wu 9291a7670a fix: properly escape reveal markdown script tag with case-insensitive regex [Security Issue]
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 13:24:48 +08:00
Yukai Huang 0963fa9525
Merge pull request #1646 from hackmdio/release/2.3.2
Release 2.3.2
2021-01-04 17:57:03 +08:00
Yukai Huang 534b2c61b9
Bump package/package.lock version
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 17:45:40 +08:00
Yukai Huang 3273a50f64 Merge branch 'master' into develop 2021-01-04 17:44:01 +08:00
Yukai Huang 87f72f8614
Merge pull request #1645 from hackmdio/release/2.3.1
Release 2.3.1
2021-01-04 17:35:58 +08:00
Yukai Huang fefe7d8e69
Update release note
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 17:21:01 +08:00
Yukai Huang dd16949222
Merge pull request #1644 from hackmdio/bugfix/bump-mermaid-deps
Bump mermaid version
2021-01-04 17:01:47 +08:00
Yukai Huang 493b86b0de
Bump cdn mermaid version
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 15:11:51 +08:00
Yukai Huang 378fb7dcce
Bump mermaid to 8.6.4
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 14:15:33 +08:00
Yukai Huang 0650179881
Merge branch 'master' into develop 2020-12-31 14:24:14 +08:00
Yukai Huang 5967fef742
Merge pull request #1642 from hackmdio/release/2.3.0
Release 2.3.0
2020-12-31 14:17:11 +08:00
Yukai Huang 30e83538e6
Bump version in package.json
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-31 11:46:29 +08:00
Yukai Huang db56ef1d3d
Update pdf broken pdf link in features.md
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-30 17:49:28 +08:00
Yukai Huang d1b4b26fe4
Update release notes
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-30 16:58:58 +08:00
Yukai Huang 4d027119f6
Merge branch 'master' into develop
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-25 16:28:10 +08:00
Yukai Huang 48f3be8ae8
Merge pull request #1632 from hackmdio/bugfix/fix-xss-in-lightbox-image-attribute
Fix xss issue for image lightbox
2020-12-25 16:21:52 +08:00
Yukai Huang 25119adf52
Merge pull request #1633 from hackmdio/bugfix/fix-mermaid-render-xss
fix: avoid eval string when putting back parsed string of mermaid
2020-12-25 16:21:40 +08:00
Yukai Huang 8e3432a3e8
Merge pull request #1637 from hackmdio/bugfix/bump-vega-deps
Bump vega dependencies
2020-12-25 16:21:26 +08:00
Yukai Huang 562e1e06c0
Merge pull request #1636 from hackmdio/bugfix/check-image-mime
Check upload image mime type
2020-12-24 17:46:38 +08:00
Yukai Huang de0f4588ac
Fix getImageMimeType mime usage
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 22:16:28 +08:00
Yukai Huang c9e23985d3
Check image type from file extension
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 15:46:19 +08:00
Yukai Huang e19e6642fb
Allow bmp/tiff image to be uploaded
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 15:45:49 +08:00
Yukai Huang c1a22a5318
Replace hard coded impl in getImageMimeType
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 15:43:14 +08:00
Yukai Huang 59fd7e71ad
Update vega cdnjs assets
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 12:18:27 +08:00
Yukai Huang 312dffe21d
Bump vega deps
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-22 17:45:53 +08:00
Yukai Huang 7a88f9d95a
Check upload image mime type
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-22 16:48:13 +08:00