From 416090376e2742f8fb257443191ac97d7fc79abd Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed, 14 Jan 2026 04:38:38 +0000 Subject: [PATCH] feat(security): sanitize user input in info panel to prevent XSS - Add `escapeHtml` utility to `src/shared/utils.ts` - Sanitize rendered values in `src/info-panel/ValueFormatter.ts` - Sanitize node titles, types, and labels in `src/info-panel/UIManager.ts` - Add unit tests verifying XSS prevention in `tests/unit/Security.test.ts` --- .jules/sentinel.md | 6 ++++++ src/info-panel/UIManager.ts | 21 +++++++++++---------- src/info-panel/ValueFormatter.ts | 8 +++++--- src/shared/utils.ts | 15 +++++++++++++++ tests/unit/Security.test.ts | 25 +++++++++++++++++++++++++ 5 files changed, 62 insertions(+), 13 deletions(-) create mode 100644 .jules/sentinel.md create mode 100644 tests/unit/Security.test.ts diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..c26da33 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,6 @@ +# Sentinel's Journal + +## 2026-01-06 - Improper DOM Manipulation XSS +**Vulnerability:** Found multiple instances of `innerHTML` being used with unsanitized user inputs (Node titles, widget values) in `UIManager.ts`. +**Learning:** This project uses direct DOM manipulation without a framework, making XSS a primary risk. Developers were manually building HTML strings. +**Prevention:** Introduced `escapeHtml` utility. Any new code using `innerHTML` MUST sanitize inputs. Prefer `textContent` where possible, or use the `escapeHtml` helper. diff --git a/src/info-panel/UIManager.ts b/src/info-panel/UIManager.ts index 46c67a4..dbe0af2 100644 --- a/src/info-panel/UIManager.ts +++ b/src/info-panel/UIManager.ts @@ -8,6 +8,7 @@ import { StateManager } from './StateManager'; import { Icons } from '../shared/icons'; import { Logger } from '../shared/logger'; +import { escapeHtml } from '../shared/utils'; import { formatValue, getValueClass, getValueAttributes, formatWidgetValue } from './ValueFormatter'; import { getCheckpointInfo, @@ -872,11 +873,11 @@ export class UIManager { } this.elements.content.innerHTML = sections.map(section => ` -