Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,8 @@
**Vulnerability:** Several `escapeHtml` implementations used DOM manipulation (`document.createElement('div').innerHTML`) or incomplete string replacement, failing to escape single and double quotes.
**Learning:** Incomplete escaping allows XSS payloads to break out of HTML attributes (e.g., `<input value="${escapeHtml(userInput)}">`).
**Prevention:** Always use `String(text)` cast combined with a comprehensive replace chain for `&`, `<`, `>`, `"`, and `'` (e.g., `&#039;`) in custom string escaping functions.

## 2024-07-08 - XSS in Markdown Rendering
**Vulnerability:** The Markdown rendering logic in `site/app.js` passed unsanitized output from `marked.parse()` directly into `innerHTML`, creating a high-severity XSS vulnerability if a user note contained malicious markdown.
**Learning:** The fallback for DOMPurify must be securely escaped text rather than the raw `rendered` HTML. Reverting to the raw unsanitized HTML on missing dependencies is a strict "fail open" pattern that leaves the app exposed.
**Prevention:** Always implement conditional sanitization that "fails closed" by gracefully degrading to safely escaped text if a sanitization library is unavailable.
6 changes: 5 additions & 1 deletion site/app.js
Original file line number Diff line number Diff line change
Expand Up @@ -2724,7 +2724,11 @@ function renderSpecsPanel() {

if (typeof marked !== 'undefined') {
const rendered = marked.parse(processedNote);
html += rendered;
if (window.DOMPurify) {
html += window.DOMPurify.sanitize(rendered, { ADD_ATTR: ['data-note-node', 'data-node'] });
} else {
html += `<pre>${processedNote.replace(/</g, '&lt;').replace(/>/g, '&gt;')}</pre>`;
}
} else {
html += `<pre>${processedNote.replace(/</g, '&lt;').replace(/>/g, '&gt;')}</pre>`;
}
Expand Down
Loading