Thanks to visit codestin.com
Credit goes to github.com

Skip to content

AttributeError raised on invalid data URI in sanitizer #188

Closed
@papachoco

Description

@papachoco

While trying to sanitize u'<html><body><audio controls="" src="data:foobar"></audio></body></html>'

I get an AttributeError exception In HTMLSanitizerMixin line 218

215: m = content_type_rgx.match(uri.path)
216: if not m:
217:      del attrs[attr]
218: if m.group('content_type') not in self.allowed_content_types:
             del attrs[attr]

Line 215 returns None , but in line 218 m is assumed to be None

Carlos

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions