Skip to content

form: HTML sanitization and remove Source from CKEditor#2093

Merged
zzacharo merged 1 commit intoCERNDocumentServer:mainfrom
zubeydecivelek:xss-injection
Sep 1, 2025
Merged

form: HTML sanitization and remove Source from CKEditor#2093
zzacharo merged 1 commit intoCERNDocumentServer:mainfrom
zubeydecivelek:xss-injection

Conversation

@zubeydecivelek
Copy link
Copy Markdown
Contributor

No description provided.

zzacharo
zzacharo previously approved these changes Aug 26, 2025
ntarocco
ntarocco previously approved these changes Aug 27, 2025
Copy link
Copy Markdown
Contributor

@ntarocco ntarocco left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes of the description fields look good.
Make sure that all other fields that receive free text input are correctly sanitizied.

@zzacharo
Copy link
Copy Markdown
Contributor

@zubeydecivelek from quickly checking, I found that we also render as HTML the translations description. Can you make sure it is sanitized?

@zzacharo zzacharo merged commit 66b68a8 into CERNDocumentServer:main Sep 1, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants