An adversarial pass found 5 Critical XSS sinks where props declared number/enum in TypeScript were interpolated raw into exported HTML attribute values, trusting the type — but nothing enforces it at runtime (AI update_props only validates node_id; deserialized saved state is untyped JSON). Fixed all 5 (NumberCounter data-target, StarRating aria-label, FormContainer method, ContactForm/InputField input type) plus 6 sibling sinks found by an exhaustive audit of every attribute-value interpolation across src/components: a JS-source injection into ContentSlider's inline setInterval script, a prototype-pollution-adjacent allowlist gap in Section's divider-shape lookup, TextareaField rows, Testimonials rating aria-label, HeroSimple textAlign, and MapEmbed zoom. Adds shared sanitizeFormMethod/sanitizeInputType allowlist helpers to utils/escape.ts alongside the existing escapeAttr/safeUrl/cssValue primitives. Every fix is TDD'd: a malicious-value test reproduces the raw injection against the pre-fix code, then passes after the fix. 502 tests green (npx vitest run), tsc + vite build green (npm run build). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
76 lines
3.3 KiB
TypeScript
76 lines
3.3 KiB
TypeScript
import { describe, test, expect } from 'vitest';
|
|
import { NumberCounter } from './NumberCounter';
|
|
|
|
const toHtml = (NumberCounter as any).toHtml;
|
|
|
|
const counters = [
|
|
{ number: 150, suffix: '+', label: 'Projects' },
|
|
{ number: 50, suffix: '+', label: 'Clients' },
|
|
];
|
|
|
|
describe('NumberCounter.toHtml deterministic + unique scope ids (thread node id, no Math.random)', () => {
|
|
test('same node id -> identical output across calls (deterministic)', () => {
|
|
const { html: html1 } = toHtml({ counters }, '', 'node-nc1');
|
|
const { html: html2 } = toHtml({ counters }, '', 'node-nc1');
|
|
expect(html1).toBe(html2);
|
|
});
|
|
|
|
test('different node ids -> distinct, non-colliding nc_ scopes (identical props, no collision)', () => {
|
|
const { html: html1 } = toHtml({ counters }, '', 'node-nc1');
|
|
const { html: html2 } = toHtml({ counters }, '', 'node-nc2');
|
|
const wrapId1 = html1.match(/<div id="(nc_[^"]+)"/)![1];
|
|
const wrapId2 = html2.match(/<div id="(nc_[^"]+)"/)![1];
|
|
expect(wrapId1).not.toBe(wrapId2);
|
|
});
|
|
|
|
test('wrapper id, per-counter ids, and inline script agree on the same uid', () => {
|
|
const { html } = toHtml({ counters }, '', 'node-nc1');
|
|
const wrapId = html.match(/<div id="(nc_[^"]+)"/)![1];
|
|
expect(html).toContain(`id="${wrapId}_n0"`);
|
|
expect(html).toContain(`id="${wrapId}_n1"`);
|
|
expect(html).toContain(`var uid="${wrapId}"`);
|
|
expect(html).toContain('document.getElementById(uid)');
|
|
expect(html).toContain('document.getElementById(uid+"_n"+i)');
|
|
});
|
|
|
|
test('no nodeId (legacy 2-arg call): still deterministic across repeated calls, not random', () => {
|
|
const { html: html1 } = toHtml({ counters }, '');
|
|
const { html: html2 } = toHtml({ counters }, '');
|
|
expect(html1).toBe(html2);
|
|
});
|
|
|
|
test('two different node ids never collide even with default (no counters override) props', () => {
|
|
const { html: html1 } = toHtml({}, '', 'node-a');
|
|
const { html: html2 } = toHtml({}, '', 'node-b');
|
|
const wrapId1 = html1.match(/<div id="(nc_[^"]+)"/)![1];
|
|
const wrapId2 = html2.match(/<div id="(nc_[^"]+)"/)![1];
|
|
expect(wrapId1).not.toBe(wrapId2);
|
|
});
|
|
});
|
|
|
|
describe('NumberCounter.toHtml counter.number is NOT runtime-type-checked -- must be sanitized before it reaches data-target', () => {
|
|
test('a malicious counter.number cannot break out of the data-target attribute to inject a <script> tag', () => {
|
|
const malicious = [
|
|
{ number: '150"><script>alert(1)</script>', suffix: '+', label: 'Evil' },
|
|
];
|
|
const { html } = toHtml({ counters: malicious }, '', 'node-nc-evil1');
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
expect(html).not.toContain('"><script>');
|
|
});
|
|
|
|
test('a malicious counter.number cannot break out of the data-target attribute to inject an onmouseover handler', () => {
|
|
const malicious = [
|
|
{ number: '150" onmouseover="alert(1)', suffix: '+', label: 'Evil' },
|
|
];
|
|
const { html } = toHtml({ counters: malicious }, '', 'node-nc-evil2');
|
|
expect(html).not.toContain('onmouseover=');
|
|
expect(html).not.toMatch(/data-target="150" onmouseover/);
|
|
});
|
|
|
|
test('normal numeric counter.number values still render as data-target="150"', () => {
|
|
const normal = [{ number: 150, suffix: '+', label: 'Projects' }];
|
|
const { html } = toHtml({ counters: normal }, '', 'node-nc-normal');
|
|
expect(html).toContain('data-target="150"');
|
|
});
|
|
});
|