CB-461: Replace SimpleMDE library with EasyMDE #501
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Tackling this long-standing security ticket for SimpleMDE, which happens to be abandoned, and won't have these security issues fixed: https://tickets.metabrainz.org/browse/SEC-163
Instead, a drop-in replacement fork EasyMDE exists ! Woo !
I also tweaked the Webpack config to allow us to import css files (and not just less files) instead of loading the css from a CDN as it was done previously.
As a pretty strong positive side effect, after testing it seems like the editor's preview option is broken in production, and will be fixed by this upgrade.