From 32185befc009a32534e111fd549a50b873ad3ff4 Mon Sep 17 00:00:00 2001 From: Luke Barnard Date: Wed, 11 Jan 2017 16:41:05 +0000 Subject: [PATCH] Only transform --- src/HtmlUtils.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/HtmlUtils.js b/src/HtmlUtils.js index ae594de960..a8fb763a8d 100644 --- a/src/HtmlUtils.js +++ b/src/HtmlUtils.js @@ -141,7 +141,7 @@ var sanitizeHtmlParams = { attribs.rel = 'noopener'; // https://mathiasbynens.github.io/rel-noopener/ return { tagName: tagName, attribs : attribs }; }, - '*': function(tagName, attribs) { + 'font': function(tagName, attribs) { // Only allow certain CSS attributes to avoid XSS attacks // Sanitizing values to avoid `url(...)` and `expression(...)` attacks if (!attribs.style) {