diff --git a/blog/bp/blog/ghost/ghost_sync.py b/blog/bp/blog/ghost/ghost_sync.py index dd803bb..19faee6 100644 --- a/blog/bp/blog/ghost/ghost_sync.py +++ b/blog/bp/blog/ghost/ghost_sync.py @@ -46,7 +46,7 @@ def _sanitize_html(html: str | None) -> str | None: }, attributes={ "*": {"class", "id", "style"}, - "a": {"href", "title", "target", "rel"}, + "a": {"href", "title", "target"}, "img": {"src", "alt", "title", "width", "height", "loading"}, "video": {"src", "controls", "width", "height", "poster"}, "audio": {"src", "controls"}, @@ -55,6 +55,7 @@ def _sanitize_html(html: str | None) -> str | None: "td": {"colspan", "rowspan"}, "th": {"colspan", "rowspan"}, }, + link_rel="noopener noreferrer", url_schemes={"http", "https", "mailto"}, )