Skip to content

Commit

Permalink
[CVE] Change version of sanitize-html to 2.7.2 and handle null condit…
Browse files Browse the repository at this point in the history
…ion for deXSS function (#3005)

Co-authored-by: reshma <[email protected]>
Co-authored-by: Harsh Gupta <[email protected]>
  • Loading branch information
3 people authored Sep 22, 2022
1 parent f8ed919 commit 8611218
Show file tree
Hide file tree
Showing 3 changed files with 22 additions and 15 deletions.
11 changes: 9 additions & 2 deletions desktop/core/src/desktop/js/utils/html/deXSS.ts
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,14 @@

import sanitizeHtml from 'sanitize-html';

const deXSS = (str?: boolean | string | number | null): string =>
(typeof str !== 'undefined' && sanitizeHtml(str as string)) || '';
const deXSS = (str?: boolean | string | number | null): string => {
if (str === null) {
return 'null';
}
if (typeof str !== 'undefined') {
return sanitizeHtml(str as string) || '';
}
return '';
};

export default deXSS;
24 changes: 12 additions & 12 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@
"react-dom": "^18.1.0",
"regenerator-runtime": "^0.13.3",
"removeNPMAbsolutePaths": "^1.0.4",
"sanitize-html": "^2.1.2",
"sanitize-html": "^2.7.2",
"select2": "3.5.1",
"selectize": "0.12.6",
"selectize-plugin-clear": "0.0.3",
Expand Down

0 comments on commit 8611218

Please sign in to comment.