hedgedoc/public
Sheogorath a2522888b2
Remove PDF export
As we already decleared in earlier versions, this patch removes PDF
export entirely. It's a not acceptable security risk for every CodiMD
instance.

The current implementation allowed to extract arbitary files from the
CodiMD host and therefore leaking secrets from a `/etc/passwd` to
CodiMD's own config files and all secrets contained in it.

Thanks to Joona for finding this vulnerability in August last year,
which lead to an emergency disabling of PDF exports in 1.5.0.

Signed-off-by: Sheogorath <sheogorath@shivering-isles.com>
2020-02-26 15:05:54 +01:00
..
css Fix font path when useCND is false and urlPath is used 2020-01-15 16:32:55 +01:00
docs Remove mattermost integration 2020-02-25 14:33:30 +01:00
fonts
js Remove PDF export 2020-02-26 15:05:54 +01:00
uploads
vendor Fix toolbar day mode 2019-05-12 20:15:46 +02:00
views Remove PDF export 2020-02-26 15:05:54 +01:00
.eslintrc.js switching to eslint for code checking 2018-11-14 23:15:36 +01:00
apple-touch-icon.png
codimd-icon-1024.png
default.md
favicon.png
screenshot.png Add new screenshot 2019-04-01 23:19:02 +02:00