Relative URIs are considered safe

This commit is contained in:
Darren Coxall 2013-12-09 14:41:37 +00:00
parent d0e587acc8
commit 59358adea8

View File

@ -718,7 +718,7 @@ func autoLink(p *parser, out *bytes.Buffer, data []byte, offset int) int {
return linkEnd - rewind return linkEnd - rewind
} }
var validUris = [][]byte{[]byte("http://"), []byte("https://"), []byte("ftp://"), []byte("mailto://")} var validUris = [][]byte{[]byte("http://"), []byte("https://"), []byte("ftp://"), []byte("mailto://"), []byte("/")}
func isSafeLink(link []byte) bool { func isSafeLink(link []byte) bool {
for _, prefix := range validUris { for _, prefix := range validUris {