Skip to content

fix(admin): escape quotes in interpolated HTML attributes - #59

Open
rexdotsh wants to merge 1 commit into
mainfrom
fix/admin-attribute-escaping
Open

rexdotsh wants to merge 1 commit into
mainfrom
fix/admin-attribute-escaping

Conversation

@rexdotsh

Copy link
Copy Markdown
Owner

Summary

  • Escape &, <, >, double and single quotes in admin-rendered values. The previous text-node serialization escaped HTML syntax but left quotes untouched, so interpolating its output inside title, aria-label, or other quoted attributes could break out of the attribute.
  • Add regression cases for mixed HTML syntax, attribute-breakout text, and pre-encoded entities.

This is audit finding #12 only; no change to API responses, OAuth or provider proxy. bun test (141 passing), bun lint, bun typecheck. Independent and unmerged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant