Comment 11 for bug 1869971

Revision history for this message
Rogan Hamby (rogan-hamby) wrote : Re: Custom CSS considered harmful

I've put a branch to use HTML::Defang on the incoming setting. I'm going to go ahead and slap a pull request on it to improve chances of eyeballs. It has worked in my limited testing, taking script calls in css and commenting them out.

https://git.evergreen-ils.org/?p=working/Evergreen.git;a=commit;h=242ea9f55465c462b66caaf6fc260c4d738d07a3