enhance: allow attribute-less MathML elements and complete the Core allowlist (#39337) (#39340)

Backport #39337 by @nschloe

Follow-up to https://github.com/go-gitea/gitea/pull/38034.

bluemonday only keeps an element without attributes if it was registered
via `AllowNoAttrs`. The MathML rules only used
`AllowAttrs(...).OnElements(...)`, so plain `<mi>x</mi>`, `<mrow>`,
`<msqrt>` and friends were stripped to bare text. Since real-world
MathML is almost entirely attribute-less elements, nearly every formula
collapsed. The existing test missed it because its only case gave every
element an attribute.

Also fills the remaining gaps against MathML Core
(https://www.w3.org/TR/mathml-core/): `rowspan` on `mtd` alongside
`columnspan`, the `maction` element with `actiontype` and `selection`,
and the reserved global attributes `intent` and `arg`.

Tests cover attribute-less round-trips, table cell spans, and `maction`
with `intent`/`arg`.

Co-authored-by: Nico Schlömer <nschloe@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
Giteabot
2026-09-17 10:45:07 -07:00
committed by GitHub
co-authored by Nico Schlömer wxiaoguang
parent 2c7a442692
commit 0b5c721971
2 changed files with 11 additions and 4 deletions
+7 -3
View File
@@ -70,6 +70,7 @@ func (st *Sanitizer) createDefaultPolicy() *bluemonday.Policy {
"mi", "mn", "mo", "mtext", "mspace", "ms",
// layout elements
"mrow", "mfrac", "msqrt", "mroot", "mstyle", "merror", "mpadded", "mphantom",
"maction", // although MDN says "maction" is deprecated, we still need to allow it, otherwise, if it is removed, the layout will be wrong
// scripting elements
"msub", "msup", "msubsup", "munder", "mover", "munderover", "mmultiscripts", "mprescripts", "none",
// tabular elements
@@ -77,10 +78,11 @@ func (st *Sanitizer) createDefaultPolicy() *bluemonday.Policy {
// semantic annotations
"semantics", "annotation", "annotation-xml",
}
policy.AllowNoAttrs().OnElements(mathMLElements...) // most MathML elements carry no attributes
policy.AllowAttrs("display", "alttext").OnElements("math")
policy.AllowAttrs(
// global presentation attributes
"dir", "displaystyle", "mathbackground", "mathcolor", "mathsize", "mathvariant", "scriptlevel",
// global attributes
"dir", "displaystyle", "mathbackground", "mathcolor", "mathsize", "mathvariant", "scriptlevel", "intent", "arg",
// operator attributes
"accent", "accentunder", "fence", "form", "largeop", "lspace", "maxsize", "minsize", "movablelimits", "rspace", "separator", "stretchy", "symmetric",
// space and padding attributes
@@ -90,7 +92,9 @@ func (st *Sanitizer) createDefaultPolicy() *bluemonday.Policy {
// table attributes
"columnalign", "columnlines", "columnspacing", "frame", "framespacing", "rowalign", "rowlines", "rowspacing",
// cell attributes
"columnspan",
"columnspan", "rowspan",
// maction attributes
"actiontype", "selection",
// annotation attribute
"encoding",
).OnElements(mathMLElements...)