mirror of
https://github.com/Tencent/WeKnora.git
synced 2026-09-24 16:29:01 +08:00
fix: remove SanitizeForDisplay from chunk handler responses
CleanMarkdown regex patterns (script, onclick=, javascript:, etc.) unconditionally delete matching substrings from chunk content, even when they appear in code blocks or inline code. JSON APIs should return raw stored data; XSS protection is the frontend markdown renderer's responsibility. SanitizeForDisplay and CleanMarkdown are retained in security.go.
This commit is contained in:
@@ -75,11 +75,6 @@ func (h *ChunkHandler) GetChunkByIDOnly(c *gin.Context) {
|
||||
return
|
||||
}
|
||||
|
||||
// 对 chunk 内容进行安全清理
|
||||
if chunk.Content != "" {
|
||||
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
|
||||
}
|
||||
|
||||
c.JSON(http.StatusOK, gin.H{
|
||||
"success": true,
|
||||
"data": chunk,
|
||||
@@ -146,13 +141,6 @@ func (h *ChunkHandler) ListKnowledgeChunks(c *gin.Context) {
|
||||
return
|
||||
}
|
||||
|
||||
// 对 chunk 内容进行安全清理
|
||||
for _, chunk := range result.Data.([]*types.Chunk) {
|
||||
if chunk.Content != "" {
|
||||
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
|
||||
}
|
||||
}
|
||||
|
||||
c.JSON(http.StatusOK, gin.H{
|
||||
"success": true,
|
||||
"data": result.Data,
|
||||
|
||||
@@ -366,9 +366,6 @@ func (h *EmbedChannelHandler) GetEmbedChunk(c *gin.Context) {
|
||||
}
|
||||
return
|
||||
}
|
||||
if chunk.Content != "" {
|
||||
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
|
||||
}
|
||||
c.JSON(http.StatusOK, gin.H{"success": true, "data": chunk})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user