Files
actual/packages
Matiss Janis Aboltins 8237da8e7b [AI] Simplify @font-face validation to only block external URLs
Remove ~210 lines of overly thorough font validation (MIME type allowlists,
base64 encoding checks, format hint validation, @font-face property allowlists,
font-family name regex) and replace with a single function that enforces the
actual security goal: rejecting non-data: URIs to prevent external resource
loading. Size limits for DoS prevention are preserved.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-19 22:06:43 +00:00
..
2026-03-15 23:16:39 +00:00
2026-03-18 08:37:04 +00:00
2026-03-18 08:37:04 +00:00
2026-03-18 08:37:04 +00:00
2026-03-18 08:37:04 +00:00