feat: add DOMPurify XSS sanitization pipeline to client-side markdown renderer
- Vendored DOMPurify at static/vendor/purify.min.js, loaded with defer in base.html - ContentRenderer.js now sanitizes marked output via DOMPurify.sanitize before processMedia - Fail-closed: render() throws if DOMPurify is undefined instead of emitting unsanitized HTML - Added _json_ld_dumps helper in seo.py to escape <>&\u2028\u2029 in JSON-LD output - Updated combine() to use the new safe dumper for all schema.org payloads
This commit is contained in:
@@ -51,6 +51,11 @@ export class ContentRenderer {
|
||||
html = "<p>" + text.replace(/\n/g, "<br>") + "</p>";
|
||||
}
|
||||
|
||||
if (typeof DOMPurify === "undefined") {
|
||||
throw new Error("DOMPurify not loaded; refusing to render untrusted HTML");
|
||||
}
|
||||
html = DOMPurify.sanitize(html);
|
||||
|
||||
html = this.processMedia(html);
|
||||
|
||||
return html;
|
||||
|
||||
Reference in New Issue
Block a user