diff --git a/cms/templates/login.html b/cms/templates/login.html index 91b54b5c74..7981ae6dc4 100644 --- a/cms/templates/login.html +++ b/cms/templates/login.html @@ -56,7 +56,6 @@ from openedx.core.djangolib.js_utils import js_escaped_string <%block name="requirejs_page"> <%static:require_page page_name="js/pages/login" class_name="LoginFactory"> - ## xss-lint: disable=mako-invalid-js-filter, mako-invalid-html-filter "${reverse('homepage') | n, js_escaped_string}" diff --git a/common/test/test-theme/cms/templates/login.html b/common/test/test-theme/cms/templates/login.html index 95ba9e9795..8479674153 100644 --- a/common/test/test-theme/cms/templates/login.html +++ b/common/test/test-theme/cms/templates/login.html @@ -54,7 +54,6 @@ from openedx.core.djangolib.js_utils import js_escaped_string <%block name="requirejs_page"> <%static:require_page page_name="js/pages/login" class_name="LoginFactory"> - ## xss-lint: disable=mako-invalid-js-filter, mako-invalid-html-filter "${reverse('homepage') | n, js_escaped_string}" diff --git a/scripts/xss_linter.py b/scripts/xss_linter.py index ceb697a14a..2d6433d6a3 100755 --- a/scripts/xss_linter.py +++ b/scripts/xss_linter.py @@ -2380,6 +2380,8 @@ class MakoTemplateLinter(BaseLinter): | # script tag end <%static:require_module(_async)?.*?> | # require js script tag start (optionally the _async version) | # require js script tag end (optionally the _async version) + <%static:require_page.*?> | # require js script tag start + | # require js script tag end <%static:webpack.*?> | # webpack script tag start | # webpack script tag end <%static:studiofrontend.*?> | # studiofrontend script tag start diff --git a/themes/red-theme/cms/templates/login.html b/themes/red-theme/cms/templates/login.html index ae55043263..b50ed21855 100644 --- a/themes/red-theme/cms/templates/login.html +++ b/themes/red-theme/cms/templates/login.html @@ -53,7 +53,6 @@ from django.utils.translation import ugettext as _ <%block name="requirejs_page"> <%static:require_page page_name="js/pages/login" class_name="LoginFactory"> - ## xss-lint: disable=mako-invalid-js-filter, mako-invalid-html-filter "${reverse('homepage') | n, js_escaped_string}"