feat(security): enhance DOM sanitization to strip dangerous URIs
Updated `sanitizeElement` to strictly remove whitespace and control characters from URI attributes before validation. This prevents bypasses like `java\tscript:` in `href`, `src`, `action`, and `formaction` attributes. Added comprehensive unit tests covering these bypass vectors. Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
This commit is contained in:
co-authored by
AEmotionStudio
parent
49f1efeeb1
commit
09da6a1d7b
+3
-1
@@ -210,7 +210,9 @@ export function sanitizeElement(element: HTMLElement): void {
|
||||
|
||||
// 2. Remove javascript: URIs in specific attributes
|
||||
if (['href', 'src', 'action', 'formaction'].includes(attrName)) {
|
||||
if (attrValue.startsWith('javascript:')) {
|
||||
// Strip all whitespace and control characters to prevent bypasses like "java\tscript:"
|
||||
const normalizedValue = attrValue.replace(/[\s\x00-\x1F\x7F]/g, '');
|
||||
if (normalizedValue.startsWith('javascript:')) {
|
||||
element.removeAttribute(attributes[i].name);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -60,6 +60,25 @@ describe('Security', () => {
|
||||
expect(form.hasAttribute('formaction')).toBe(false);
|
||||
});
|
||||
|
||||
it('should remove obscured javascript: URIs (whitespace bypass)', () => {
|
||||
const window = new Window();
|
||||
const document = window.document;
|
||||
const link = document.createElement('a');
|
||||
|
||||
// Bypass attempts: tabs, newlines, spaces
|
||||
link.setAttribute('href', 'java\tscript:alert(1)');
|
||||
sanitizeElement(link as unknown as HTMLElement);
|
||||
expect(link.hasAttribute('href')).toBe(false);
|
||||
|
||||
link.setAttribute('href', 'java\nscript:alert(1)');
|
||||
sanitizeElement(link as unknown as HTMLElement);
|
||||
expect(link.hasAttribute('href')).toBe(false);
|
||||
|
||||
link.setAttribute('href', ' javascript:alert(1)');
|
||||
sanitizeElement(link as unknown as HTMLElement);
|
||||
expect(link.hasAttribute('href')).toBe(false);
|
||||
});
|
||||
|
||||
it('should preserve safe URLs', () => {
|
||||
const window = new Window();
|
||||
const document = window.document;
|
||||
|
||||
Reference in New Issue
Block a user