From 885fa8f1fc4a9264575aad125310e0eaf4c82749 Mon Sep 17 00:00:00 2001 From: mattwr18 Date: Mon, 6 Jan 2020 15:39:26 +0100 Subject: [PATCH] Parse xss before extracting mentions/hashtags --- backend/src/middleware/index.js | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/backend/src/middleware/index.js b/backend/src/middleware/index.js index 9c68d8c00..16becb7a0 100644 --- a/backend/src/middleware/index.js +++ b/backend/src/middleware/index.js @@ -18,25 +18,26 @@ import sentry from './sentryMiddleware' export default schema => { const middlewares = { - permissions, sentry, + permissions, + xss, activityPub, validation, sluggify, excerpt, + email, notifications, hashtags, - xss, softDelete, user, includedFields, orderBy, - email, } let order = [ 'sentry', 'permissions', + 'xss', // 'activityPub', disabled temporarily 'validation', 'sluggify', @@ -44,7 +45,6 @@ export default schema => { 'email', 'notifications', 'hashtags', - 'xss', 'softDelete', 'user', 'includedFields',