/** * @fileoverview Allowlist-based HTML sanitizer for markdown-rendered, agent/transcript-derived * content that is subsequently assigned via innerHTML (response viewer, attachment markdown * preview, message bodies). * * Security (COD-56): the previous sanitizer was a hand-rolled DENYLIST — it removed a fixed * set of tags (script/iframe/object/embed/form/base/meta/link/style), stripped on* attrs and a * few dangerous URL schemes, then re-serialized. Denylists are mXSS-prone: they did not strip * `svg`/`math` (which carry their own foreign-namespace parsing rules and can smuggle script via * namespace confusion), did not strip `style` attributes (CSS `expression()`/`url(javascript:)` * on legacy engines), and had no positive allowlist, so any tag/attribute not explicitly named * survived. `marked` runs with raw-HTML passthrough, so crafted HTML echoed by an agent flows * straight into this function. * * This module replaces that with DOMPurify (Cure53), an allowlist sanitizer that is the * industry standard for mXSS defense. It is configured to allow exactly the tag/attribute set * that markdown rendering legitimately produces (headings, lists, code, blockquotes, links, * tables, images with safe src) and to FORBID `style`/`svg`/`math` plus all event handlers and * dangerous URL schemes. * * Cross-environment: in the browser this file runs as a classic