NoEventAttributesExtension
Ecng.Markdown.Extensions
Removes event-handler properties ("on*") that generic attributes put on any node, so untrusted markdown cannot attach script through "{onclick=...}". Runs on every document the pipeline parses, including the inner content a styled inline renders on its own.
Implements: IMarkdownExtension
Methods
Setup
public void Setup(MarkdownPipelineBuilder pipeline)
noEventAttributesExtension.Setup(pipeline)
Setup
public void Setup(MarkdownPipeline pipeline, IMarkdownRenderer renderer)
noEventAttributesExtension.Setup(pipeline, renderer)