- Security fix/Breaking change (Imagelib): Require allowedImageLibOrigins

config array be set with safe origins or otherwise reject `postMessage`
  messages in case from untrusted sources
- Security fix/Breaking change (xdomain): Namespace xdomain file to avoid
  it being used to modify non-xdomain storage
- Security fix (Imagelib): Expose `dropXMLInternalSubset` to extensions
  for preventing billion laughs attack (and use in Imagelib)
This commit is contained in:
Brett Zamir
2018-09-24 20:59:47 +08:00
parent 25ed8ad465
commit 11baad0402
10 changed files with 55 additions and 25 deletions

View File

@@ -31,7 +31,7 @@ import {
preventClickDefault, snapToGrid, walkTree, walkTreePost,
getBBoxOfElementAsPath, convertToPath, toXml, encode64, decode64,
dataURLToObjectURL, createObjectURL,
getVisibleElements,
getVisibleElements, dropXMLInteralSubset,
init as utilsInit, getBBox as utilsGetBBox, getStrokedBBoxDefaultVisible
} from './utilities.js';
import * as history from './history.js';
@@ -7127,6 +7127,7 @@ this.clear();
* @property {module:history.HistoryCommand} BatchCommand
* @property {module:history.HistoryCommand} ChangeElementCommand
* @property {module:utilities.decode64} decode64
* @property {module:utilities.dropXMLInteralSubset} dropXMLInteralSubset
* @property {module:utilities.encode64} encode64
* @property {module:svgcanvas~ffClone} ffClone
* @property {module:svgcanvas~findDuplicateGradient} findDuplicateGradient
@@ -7166,6 +7167,7 @@ this.getPrivateMethods = function () {
BatchCommand,
ChangeElementCommand,
decode64,
dropXMLInteralSubset,
encode64,
ffClone,
findDefs,