diff --git a/app/assets/javascripts/discourse/dialects/dialect.js b/app/assets/javascripts/discourse/dialects/dialect.js index 6dfe71cfb2c..c3071ae35c3 100644 --- a/app/assets/javascripts/discourse/dialects/dialect.js +++ b/app/assets/javascripts/discourse/dialects/dialect.js @@ -42,7 +42,6 @@ function processTextNodes(node, event, emitter) { for (var j=1; j$/m.exec(n[1])) { + if (n && n.length === 2 && n[0] === "p" && /^$/.exec(n[1])) { // Remove paragraphs around comment-only nodes. tree[i] = n[1]; } else { diff --git a/test/javascripts/lib/markdown_test.js b/test/javascripts/lib/markdown_test.js index e46ebc946e1..87d891ae219 100644 --- a/test/javascripts/lib/markdown_test.js +++ b/test/javascripts/lib/markdown_test.js @@ -354,6 +354,8 @@ test("sanitize", function() { equal(sanitize("draw me!"), "draw me!"); cooked("[the answer](javascript:alert(42))", "

the answer

", "it prevents XSS"); + + cooked("\n", "


<!-- -->

", "it doesn't circumvent XSS with comments"); }); test("URLs in BBCode tags", function() {