feat(security): enhance DOM sanitization to strip dangerous URIs

Updated `sanitizeElement` to strictly remove whitespace and control characters from URI attributes before validation.
This prevents bypasses like `java\tscript:` in `href`, `src`, `action`, and `formaction` attributes.
Added comprehensive unit tests covering these bypass vectors.

Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
This commit is contained in:
google-labs-jules[bot]
2026-02-10 03:35:57 +00:00
co-authored by AEmotionStudio
parent 49f1efeeb1
commit 09da6a1d7b
2 changed files with 22 additions and 1 deletions
+3 -1
View File
@@ -210,7 +210,9 @@ export function sanitizeElement(element: HTMLElement): void {
// 2. Remove javascript: URIs in specific attributes
if (['href', 'src', 'action', 'formaction'].includes(attrName)) {
if (attrValue.startsWith('javascript:')) {
// Strip all whitespace and control characters to prevent bypasses like "java\tscript:"
const normalizedValue = attrValue.replace(/[\s\x00-\x1F\x7F]/g, '');
if (normalizedValue.startsWith('javascript:')) {
element.removeAttribute(attributes[i].name);
}
}
+19
View File
@@ -60,6 +60,25 @@ describe('Security', () => {
expect(form.hasAttribute('formaction')).toBe(false);
});
it('should remove obscured javascript: URIs (whitespace bypass)', () => {
const window = new Window();
const document = window.document;
const link = document.createElement('a');
// Bypass attempts: tabs, newlines, spaces
link.setAttribute('href', 'java\tscript:alert(1)');
sanitizeElement(link as unknown as HTMLElement);
expect(link.hasAttribute('href')).toBe(false);
link.setAttribute('href', 'java\nscript:alert(1)');
sanitizeElement(link as unknown as HTMLElement);
expect(link.hasAttribute('href')).toBe(false);
link.setAttribute('href', ' javascript:alert(1)');
sanitizeElement(link as unknown as HTMLElement);
expect(link.hasAttribute('href')).toBe(false);
});
it('should preserve safe URLs', () => {
const window = new Window();
const document = window.document;