diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..c26da33 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,6 @@ +# Sentinel's Journal + +## 2026-01-06 - Improper DOM Manipulation XSS +**Vulnerability:** Found multiple instances of `innerHTML` being used with unsanitized user inputs (Node titles, widget values) in `UIManager.ts`. +**Learning:** This project uses direct DOM manipulation without a framework, making XSS a primary risk. Developers were manually building HTML strings. +**Prevention:** Introduced `escapeHtml` utility. Any new code using `innerHTML` MUST sanitize inputs. Prefer `textContent` where possible, or use the `escapeHtml` helper. diff --git a/src/info-panel/UIManager.ts b/src/info-panel/UIManager.ts index 46c67a4..dbe0af2 100644 --- a/src/info-panel/UIManager.ts +++ b/src/info-panel/UIManager.ts @@ -8,6 +8,7 @@ import { StateManager } from './StateManager'; import { Icons } from '../shared/icons'; import { Logger } from '../shared/logger'; +import { escapeHtml } from '../shared/utils'; import { formatValue, getValueClass, getValueAttributes, formatWidgetValue } from './ValueFormatter'; import { getCheckpointInfo, @@ -872,11 +873,11 @@ export class UIManager { } this.elements.content.innerHTML = sections.map(section => ` -