fix: preserve allowed iframe query parameters (#5295)

Co-authored-by: Prospector <6166773+Prospector@users.noreply.github.com>
This commit is contained in:
Kevin
2026-02-09 16:17:37 +01:00
committed by GitHub
parent 0facf26b04
commit e80d7730ca

View File

@@ -53,7 +53,7 @@ export const configuredXss = new FilterXSS({
continue
}
const newSearchParams = new URLSearchParams()
const newSearchParams = new URLSearchParams(url.searchParams)
url.searchParams.forEach((value, key) => {
if (!source.allowedParameters.some((param) => param.test(`${key}=${value}`))) {
newSearchParams.delete(key)