mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 08:29:42 +02:00
Replace markdown denylist sanitizer with vendored DOMPurify (mXSS hardening)
The previous _sanitizeHtml was a denylist over agent/transcript markdown rendered via innerHTML; it missed style attributes and the svg/math mXSS namespaces — e.g. <svg><style><img src=x onerror=alert(1)></style></svg> re-serialized into a live <img onerror>. Vendor DOMPurify 3.4.8 (allowlist) following the existing marked.min.js vendor pattern (same-origin, CSP script-src 'self'; not in package.json so no lockfile drift). New sanitize-html.js wires a hardened allowlist config (FORBID style/svg/math/script/iframe/object/embed/form; no data attrs); app.js _sanitizeHtml delegates to it with a fail-closed escape-all fallback. index.html loads dompurify -> sanitize-html -> app.js (defer); build.mjs minifies + content-hashes sanitize-html.js. Test: test/markdown-sanitizer.test.ts (jsdom, real shipping artifacts) — mXSS payloads neutralized + legit markdown preserved.
This commit is contained in:
@@ -39,6 +39,9 @@
|
||||
<script defer src="vendor/xterm-addon-unicode11.min.js"></script>
|
||||
<script defer src="vendor/xterm-zerolag-input.js"></script>
|
||||
<script defer src="vendor/marked.min.js"></script>
|
||||
<!-- DOMPurify (allowlist HTML sanitizer for rendered markdown).
|
||||
Must load before sanitize-html.js (which wires it) and app.js (which calls it). -->
|
||||
<script defer src="vendor/dompurify.min.js"></script>
|
||||
<!-- Synchronous mobile detection — runs before first paint to prevent panel flash -->
|
||||
<script>if(window.innerWidth<768||(('ontouchstart' in window||navigator.maxTouchPoints>0)&&window.innerWidth<1024))document.documentElement.classList.add('mobile-init');</script>
|
||||
<!-- Synchronous skin selection — runs before first paint to prevent theme flash -->
|
||||
@@ -1907,6 +1910,8 @@
|
||||
<script defer src="notification-manager.js"></script>
|
||||
<script defer src="keyboard-accessory.js"></script>
|
||||
<script defer src="input-cjk.js"></script>
|
||||
<!-- Hardened markdown HTML sanitizer (wires DOMPurify). Must precede app.js. -->
|
||||
<script defer src="sanitize-html.js"></script>
|
||||
<script defer src="app.js"></script>
|
||||
<script defer src="terminal-ui.js"></script>
|
||||
<script defer src="respawn-ui.js"></script>
|
||||
|
||||
Reference in New Issue
Block a user