Skip to content

Commit cb6f6f9

Browse files
Orrisontonghuaroot
andauthored
[ADVAPP-2700]: Resolve potential security scenario in Customer Advisors (#2588)
Fix XSS vulnerability by sanitizing advisor message content in transcript modal Signed-off-by: Kevin Ullyott <kevin.ullyott@canyongbs.com> Co-authored-by: tonghuaroot <tonghuaroot@gmail.com>
1 parent db14561 commit cb6f6f9

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

app-modules/ai/resources/views/filament/widgets/qna-advisor-transcript-modal.blade.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ class="{{ $message->is_advisor ? 'text-gray-600 dark:text-gray-300' : 'text-prim
5454
<div
5555
class="{{ $message->is_advisor ? 'text-gray-900 dark:text-gray-100 dark:prose-invert prose-p:mb-3 prose-p:leading-relaxed' : 'text-white prose-invert prose-p:mb-3 prose-p:leading-relaxed' }} prose prose-sm max-w-none leading-relaxed"
5656
>
57-
{!! str($message->content)->markdown() !!}
57+
{{ str($message->content)->markdown()->sanitizeHtml()->toHtmlString() }}
5858
</div>
5959
</div>
6060
</div>

0 commit comments

Comments
 (0)