fix(builder): sanitize HtmlBlock/Countdown/Gallery JS contexts
Entity-escaping alone doesn't protect JS-string or raw-HTML sinks:
- HtmlBlock.toHtml exported props.code raw; now runs it through the
same purifyHtml (DOMPurify) config already used for the live editor
preview, so <script>/on*= payloads can't survive export either.
- Countdown.toHtml interpolated targetDate directly into
`new Date("${targetDate}")` inside an inline <script> -- a value
like `2026-01-01");alert(1)//` broke out of the string literal. Now
validated against a strict date/datetime shape and JSON.stringify'd
before embedding, falling back to `new Date()` for anything invalid.
- Gallery.toHtml's lightbox used
`onclick="${id}_open('${esc(img.src)}')"`, which a single quote in
img.src could break out of. Replaced with a `data-lb-src` attribute
per thumbnail and one delegated click listener on the grid
(`e.target.closest('[data-lb-src]')`) instead of a per-item inline
handler string.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
import { describe, test, expect } from 'vitest';
|
||||
import { HtmlBlock } from './HtmlBlock';
|
||||
|
||||
const toHtml = (HtmlBlock as any).toHtml;
|
||||
|
||||
describe('HtmlBlock.toHtml sanitizes raw code (A4.1)', () => {
|
||||
test('strips <script> and on-handlers from exported output', () => {
|
||||
const { html } = toHtml({ code: '<script>alert(1)</script><p onclick="x">hi</p>' }, '');
|
||||
expect(html).not.toContain('<script');
|
||||
expect(html).not.toContain('onclick');
|
||||
expect(html).toContain('<p>hi</p>');
|
||||
});
|
||||
});
|
||||
@@ -140,6 +140,7 @@ HtmlBlock.craft = {
|
||||
/* ---------- HTML export ---------- */
|
||||
|
||||
(HtmlBlock as any).toHtml = (props: HtmlBlockProps, _childrenHtml: string) => {
|
||||
// Output the raw code as-is
|
||||
return { html: props.code || '' };
|
||||
// Run through the same DOMPurify config used for the live editor preview
|
||||
// so exported pages can't carry <script>/on*= payloads either.
|
||||
return { html: purifyHtml(props.code || '') };
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user