fb4e9f87be492f069960a40e61d610af888b8084
cssPropsToString() joined raw CSSProperties values into a style="..." attribute with zero escaping, so any component spreading user-controlled values into inline styles (background-image url(), etc.) could break out of the attribute or inject a second declaration -- this is what made BackgroundSection/HeroSimple/CallToAction/Section's bg-image url() sites (flagged in the A3 brief) safe without needing a per-call- site fix, since they already route through this helper. Each string value is now sanitized: url(...) contents are validated through safeUrl and re-wrapped escaped, stray `;` (the only way to inject a second live declaration) is stripped, and any raw `"` is entity-encoded so it can't terminate the attribute early. Legitimate multi-part values (box-shadow, gradients) that contain none of these characters pass through byte-identical. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
Visual drag-and-drop website builder using GrapesJS
Languages
TypeScript
61.2%
HTML
17.1%
JavaScript
17%
CSS
3.6%
PHP
0.8%
Other
0.3%