diff --git a/app/Core/Helper.php b/app/Core/Helper.php index 34a5e6ab3..1dea832a0 100644 --- a/app/Core/Helper.php +++ b/app/Core/Helper.php @@ -502,7 +502,7 @@ class Helper public function markdown($text, array $link = array()) { $parser = new Markdown($link, $this); - $parser->setMarkupEscaped(true); + $parser->setMarkupEscaped(MARKDOWN_ESCAPED); return $parser->text($text); } diff --git a/app/constants.php b/app/constants.php index 82d26f2c1..8c23da81d 100644 --- a/app/constants.php +++ b/app/constants.php @@ -74,3 +74,5 @@ defined('ENABLE_XFRAME') or define('ENABLE_XFRAME', true); // Default files directory defined('FILES_DIR') or define('FILES_DIR', 'data/files/'); +// Escape html inside markdown text +define('MARKDOWN_ESCAPED', true); diff --git a/config.default.php b/config.default.php index eb9ad1b8e..0306ea35c 100644 --- a/config.default.php +++ b/config.default.php @@ -127,3 +127,6 @@ define('ENABLE_HSTS', true); // Enable or disable "X-Frame-Options: DENY" HTTP header define('ENABLE_XFRAME', true); + +// Escape html inside markdown text +define('MARKDOWN_ESCAPED', true);