Commit Graph

1166 Commits

Author SHA1 Message Date
Yukai Huang 0fb184c2d8
Merge branch 'master' into develop 2021-01-26 01:58:26 +08:00
Yukai Huang 452f9ac124
Merge pull request #1650 from hackmdio/bugfix/fix-reveal-markdown-stored-xss
Fix slide mode stored XSS
2021-01-25 16:50:23 +08:00
Yukai Huang 5b4c7ef4bb
Merge pull request #1651 from hackmdio/bugfix/fix-pdf-embed-freeze-on-safari-big-sur
fix: avoid insert embed tag on the main thread which cause Safari on Big Sur freezing
2021-01-25 15:00:57 +08:00
Yukai Huang 14e93fdb24
Merge pull request #1652 from hackmdio/bugfix/fix-vimeo-jsonp-callback
fix: vimeo won't show up due to the jsonp callback data unable be parsed with jQuery
2021-01-25 15:00:40 +08:00
Raccoon d74d30cc37
fix: feature section slide mode link broken
Signed-off-by: Raccoon <raccoon@hackmd.io>
2021-01-22 15:29:08 +08:00
Max Wu 2b9affbc08 fix: code style
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:35:16 +08:00
Max Wu 47bab4266b fix: vimeo won't show up due to the jsonp callback data unable be parsed with jQuery
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:35:16 +08:00
Max Wu a1e3768f98 fix: avoid insert embed tag on the main thread which cause Safari on Big Sur freezing
upgrade pdfobject to version 2.2.4

Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 14:23:45 +08:00
Max Wu c47f0f0c71 fix: remove reveal options of dependencies which allow import user defined resources [Security Issue]
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 13:24:48 +08:00
Max Wu 9291a7670a fix: properly escape reveal markdown script tag with case-insensitive regex [Security Issue]
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2021-01-21 13:24:48 +08:00
Yukai Huang fefe7d8e69
Update release note
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 17:21:01 +08:00
Yukai Huang 493b86b0de
Bump cdn mermaid version
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2021-01-04 15:11:51 +08:00
Yukai Huang db56ef1d3d
Update pdf broken pdf link in features.md
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-30 17:49:28 +08:00
Yukai Huang d1b4b26fe4
Update release notes
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-30 16:58:58 +08:00
Yukai Huang 4d027119f6
Merge branch 'master' into develop
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-25 16:28:10 +08:00
Yukai Huang 48f3be8ae8
Merge pull request #1632 from hackmdio/bugfix/fix-xss-in-lightbox-image-attribute
Fix xss issue for image lightbox
2020-12-25 16:21:52 +08:00
Yukai Huang 25119adf52
Merge pull request #1633 from hackmdio/bugfix/fix-mermaid-render-xss
fix: avoid eval string when putting back parsed string of mermaid
2020-12-25 16:21:40 +08:00
Yukai Huang 59fd7e71ad
Update vega cdnjs assets
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-23 12:18:27 +08:00
Max Wu 568355acf5 fix: properly validate mermaid syntax and handle parse error
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2020-12-21 14:56:48 +08:00
Max Wu 064dfb7865 fix: disable prefer-const lint rule for mermaid block text string
Signed-off-by: Max Wu <jackymaxj@gmail.com>
2020-12-21 14:49:34 +08:00
Yukai Huang 5fee551d69
Fix fretboard title xss issue
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-21 14:25:47 +08:00
Max Wu 8d9a9ab0b2 fix: avoid eval string when putting back parsed string of mermaid
where has stored XSS issue

Signed-off-by: Max Wu <jackymaxj@gmail.com>
2020-12-21 14:24:46 +08:00
Yukai Huang 26a2c746d3
Escape attributes in lightbox image
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-12-21 14:10:03 +08:00
Yukai Huang cebd5e7da9
Merge pull request #1574 from santigl/spellcheck-en-gb-dict
Spellcheck: add en_GB dictionary
2020-09-10 16:14:04 +08:00
TAKAHASHI Tamotsu 341591d10b Fix ui-edit and ui-both button in night mode
Fix #1539

Signed-off-by: Tamotsu Takahashi <ttakah@gmail.com>
2020-09-10 16:24:14 +09:00
Santiago Gil 1585abdb84 Spellcheck: add en_GB dictionary
Signed-off-by: Santiago Gil <santix91@gmail.com>
2020-08-13 23:02:13 +01:00
Yukai Huang cfbae54ef8
Allow specifying option for graphviz
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-08-13 17:46:42 +08:00
Yukai Huang 24de5a54c9
Merge pull request #1559 from hackmdio/feature/update-delete-note-api
Update and delete note api
2020-08-13 15:55:10 +08:00
Yukai Huang 038fac1e91
Add fretboard example and link to features.md
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-08-13 15:01:04 +08:00
Yukai Huang 12b8f09d52
Finetune fretboard css
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-08-12 17:21:21 +08:00
Yukai Huang 94aa54b495
Support empty fretboard title
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-08-12 17:19:20 +08:00
James Tsai b3cf98b329 Fix linter
Signed-off-by: James Tsai <jamesscamel@gmail.com>
2020-07-27 18:01:10 +08:00
Yukai Huang fad19473e3
Add mindmap example to features
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-20 13:55:25 +08:00
Yukai Huang 40084b25c9
Add fretboard to features.md
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-20 13:36:07 +08:00
Yukai Huang 0161d07b36
Update release notes
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-20 10:36:51 +08:00
Yukai Huang 8e72eb5aca
Merge pull request #1548 from hackmdio/feature/list-my-note-api
List-my-note API
2020-07-15 17:13:35 +08:00
Yukai Huang 0b164a0b93
Fix background image ref when urlpath is set
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-10 16:16:51 +08:00
Yukai Huang 5e608a9da8
Fix font loading when urlpath is set
Use copy webpack plugin instead. In the old fasion

Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-10 16:08:45 +08:00
Yukai Huang 70de439436 Fix baseUrl not replaced correctly in #1378
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-10 11:18:28 +08:00
Yukai Huang 91fb54539a
Merge pull request #1546 from schokotets/develop
feature: pass-through yaml metadata image to html meta tag
2020-07-10 10:33:55 +08:00
Yukai Huang 051789b41c
Merge pull request #1498 from zent00/develop
Update Simplified Chinese translation and fix typography
2020-07-10 10:32:43 +08:00
Yukai Huang 731cec6966
Revert mdTokens changes
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 17:25:07 +08:00
Yukai Huang cec3c45c2e Update features.md
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 17:14:10 +08:00
Yukai Huang 1adf1221c6 Escape html for table cell
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 17:14:10 +08:00
Yukai Huang b29d2c0a31 Implement cspreview renderer
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 17:14:10 +08:00
Max Wu a569881fcf
Merge pull request #1463 from hackmdio/feature/image-lightbox 2020-07-09 16:41:39 +08:00
Raccoon e9cf0431d4
Merge branch 'develop' into feat/mindmap 2020-07-09 15:48:28 +08:00
Yukai Huang e3a6669c7e Larger draggable area
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 14:01:22 +08:00
Yukai Huang 82253f496f Support keyboard navigation
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 14:01:22 +08:00
Yukai Huang c22ce8da60 Dark mode
Signed-off-by: Yukai Huang <yukaihuangtw@gmail.com>
2020-07-09 14:01:22 +08:00