Files
Codeman/src
arkonandClaude Opus 4.6 bd9797b68c fix: sanitize case names from filesystem to prevent XSS in inline handlers
Filter readdir and linked-case names through /^[a-zA-Z0-9_-]+$/ before
returning them from GET /api/cases. Prevents XSS via maliciously-named
directories reaching frontend inline onclick handlers where escapeHtml
is insufficient (HTML-decoded back to quotes before JS execution).

Also fix misleading "Drag or use arrows" hint (no drag-and-drop exists).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-03 03:58:29 +02:00
..
2026-03-27 01:43:59 +01:00
2026-03-27 01:43:59 +01:00
2026-03-28 16:49:55 +01:00
2026-02-18 12:51:35 +01:00
2026-03-27 01:43:59 +01:00
2026-03-27 01:43:59 +01:00