From cceb24ed8f9b4f1ed0c460a433a6845c38286aa7 Mon Sep 17 00:00:00 2001 From: "Claude (Codeman maintainer)" Date: Sun, 14 Jun 2026 22:21:13 +0200 Subject: [PATCH] fix(sanitizer): enforce the curated allowlist + make the test run order-independently MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review fixes on top of the DOMPurify mXSS hardening: - Remove `USE_PROFILES: { html: true }` from the sanitize-html.js config. DOMPurify treats USE_PROFILES and ALLOWED_TAGS/ALLOWED_ATTR as mutually exclusive — with a profile set it resets the allow-lists to the full HTML profile and silently ignores the curated lists, so the tight markdown-only allowlist was dead config (still XSS-safe via FORBID + core, but far broader than intended: