Skip to content

Fix code scanning alert no. 29: Incomplete multi-character sanitization#312

Draft
xheiop wants to merge 1 commit intomasterfrom
alert-autofix-29
Draft

Fix code scanning alert no. 29: Incomplete multi-character sanitization#312
xheiop wants to merge 1 commit intomasterfrom
alert-autofix-29

Conversation

@xheiop
Copy link
Owner

@xheiop xheiop commented Nov 4, 2024

Fixes https://github.com/techmovie/easy-upload/security/code-scanning/29

To fix the problem, we should use a well-tested sanitization library to ensure that all potentially dangerous HTML tags and attributes are removed. The sanitize-html library is a good choice for this purpose. This library will handle all corner cases and ensure effective sanitization.

We will replace the current sanitization logic with a call to sanitize-html. This will involve importing the library and using it to sanitize the innerHTML content.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant