mirror of https://github.com/garrytan/gstack.git
With --allow-network off, the sanitizer stripped script/iframe/link but let Chromium fetch remote resources at print time through four raw-HTML vectors: <style> @import (any form), remote url() in <style> blocks and inline style attributes (incl. protocol-relative //), srcset with a remote candidate (Chromium prefers srcset over the inlined src), and remote src/poster on video/audio/source/track. All neutralized at the sanitizer; remote <img src> is deliberately left for the image inliner so its blocked-remote placeholder still fires, and url() mentions in prose/code spans stay untouched. Fork's test suite ported verbatim (12 cases incl. the end-to-end render assertion), verified RED against the old sanitizer. Ported from time-attack/gstack (GStack 2). Co-authored-by: Sina Matian <sina@time-attack.dev> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| browseClient.ts | ||
| cli.ts | ||
| commands.ts | ||
| diagram-prepass.ts | ||
| image-policy.ts | ||
| image-size.ts | ||
| orchestrator.ts | ||
| pdftotext.ts | ||
| print-css.ts | ||
| render.ts | ||
| setup.ts | ||
| smartypants.ts | ||
| types.ts | ||