591a51dcc2
An adversarial pass found 5 Critical XSS sinks where props declared number/enum in TypeScript were interpolated raw into exported HTML attribute values, trusting the type — but nothing enforces it at runtime (AI update_props only validates node_id; deserialized saved state is untyped JSON). Fixed all 5 (NumberCounter data-target, StarRating aria-label, FormContainer method, ContactForm/InputField input type) plus 6 sibling sinks found by an exhaustive audit of every attribute-value interpolation across src/components: a JS-source injection into ContentSlider's inline setInterval script, a prototype-pollution-adjacent allowlist gap in Section's divider-shape lookup, TextareaField rows, Testimonials rating aria-label, HeroSimple textAlign, and MapEmbed zoom. Adds shared sanitizeFormMethod/sanitizeInputType allowlist helpers to utils/escape.ts alongside the existing escapeAttr/safeUrl/cssValue primitives. Every fix is TDD'd: a malicious-value test reproduces the raw injection against the pre-fix code, then passes after the fix. 502 tests green (npx vitest run), tsc + vite build green (npm run build). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
68 lines
3.1 KiB
TypeScript
68 lines
3.1 KiB
TypeScript
import { describe, test, expect } from 'vitest';
|
|
import { MapEmbed } from './MapEmbed';
|
|
|
|
const toHtml = (MapEmbed as any).toHtml;
|
|
|
|
describe('MapEmbed.toHtml iframe accessibility (F2.4)', () => {
|
|
test('iframe has a non-empty title attribute', () => {
|
|
const { html } = toHtml({ address: 'New York, NY' }, '');
|
|
expect(html).toMatch(/<iframe[^>]*title="[^"]+"/);
|
|
});
|
|
|
|
test('title reflects the configured address', () => {
|
|
const { html } = toHtml({ address: 'Golden Gate Bridge' }, '');
|
|
expect(html).toContain('title="Map of Golden Gate Bridge"');
|
|
});
|
|
});
|
|
|
|
describe('MapEmbed.toHtml iframe src ampersand encoding (F-export review Minor)', () => {
|
|
test('the iframe src (built by string concatenation with literal &) emits & in the attribute, not a raw &', () => {
|
|
const { html } = toHtml({ address: 'New York, NY', zoom: 14 }, '');
|
|
const srcMatch = html.match(/<iframe src="([^"]+)"/);
|
|
expect(srcMatch).toBeTruthy();
|
|
// The raw src is `...q=...&z=14&output=embed` -- concatenated with
|
|
// literal `&`s -- so the emitted attribute must HTML-encode them.
|
|
expect(srcMatch![1]).toContain('&z=14');
|
|
expect(srcMatch![1]).toContain('&output=embed');
|
|
expect(srcMatch![1]).not.toMatch(/&(?!amp;)/);
|
|
});
|
|
});
|
|
|
|
describe('MapEmbed.toHtml address/zoom/height XSS hardening', () => {
|
|
test('a malicious address cannot break out of the src or title attribute', () => {
|
|
const malicious = 'X" onerror="alert(1)';
|
|
const { html } = toHtml({ address: malicious }, '');
|
|
expect(html).not.toContain('onerror="alert(1)"');
|
|
});
|
|
|
|
test('a wrong-typed zoom (string with attribute-breakout chars) cannot break out of the src attribute', () => {
|
|
const malicious = '14"><script>alert(1)</script>' as any;
|
|
const { html } = toHtml({ address: 'X', zoom: malicious }, '');
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
expect(html).not.toContain('"><script');
|
|
});
|
|
|
|
test('a wrong-typed zoom is coerced to a safe numeric value in the exported URL (defense in depth beyond escaping)', () => {
|
|
const malicious = '14"><script>alert(1)</script>' as any;
|
|
const { html } = toHtml({ address: 'X', zoom: malicious }, '');
|
|
const srcMatch = html.match(/<iframe src="([^"]+)"/);
|
|
expect(srcMatch).toBeTruthy();
|
|
// Decode the entity-escaped src back to a plain string and confirm the
|
|
// `z=` param is a bare, well-formed number -- not the raw attacker string.
|
|
const decoded = srcMatch![1].replace(/&/g, '&').replace(/"/g, '"').replace(/</g, '<').replace(/>/g, '>');
|
|
expect(decoded).toMatch(/[&?]z=\d+(&|$)/);
|
|
});
|
|
|
|
test('a malicious height cannot break out of the iframe style attribute', () => {
|
|
const malicious = '400px" onmouseover="alert(1)';
|
|
const { html } = toHtml({ address: 'X', height: malicious }, '');
|
|
expect(html).not.toContain('onmouseover="alert(1)"');
|
|
});
|
|
|
|
test('a normal zoom/height still renders correctly', () => {
|
|
const { html } = toHtml({ address: 'X', zoom: 10, height: '300px' }, '');
|
|
expect(html).toContain('z=10');
|
|
expect(html).toContain('height:300px');
|
|
});
|
|
});
|