diff --git a/packages/devkit/src/util.js b/packages/devkit/src/util.js index 1710bbff7..eefffdc0f 100644 --- a/packages/devkit/src/util.js +++ b/packages/devkit/src/util.js @@ -450,16 +450,34 @@ export default class Util { * @static */ static htmlSanitize(html) { - const annotationRegex = /\/; + const annotationRegex = /(]*>)([\s\S]*?)(<\/annotation>)/i; // Get all the annotation content including the tags. const annotation = html.match(annotationRegex); + // Sanitize html code without removing our supported MathML tags and attributes. html = DOMPurify.sanitize(html, { ADD_TAGS: ["semantics", "annotation", "mstack", "msline", "msrow", "none"], ADD_ATTR: ["linebreak", "charalign", "stackalign"], }); - // Readd old annotation content. - return html.replace(annotationRegex, annotation); + + if (annotation) { + const startTag = annotation[1]; + const content = annotation[2]; + const endTag = annotation[3]; + + // Encode strictly <, >, and & to their HTML entities to force the browser to render any HTML as text. + const safeContent = content + .replace(/&/g, "&") + .replace(//g, ">"); + + const safeAnnotation = startTag + safeContent + endTag; + + // Re-insert the safely encoded annotation content. + html = html.replace(annotationRegex, safeAnnotation); + } + + return html; } /**