1. 06 Feb, 2026 1 commit
    • 🔒 fix(security): sanitize AI-generated HTML to prevent XSS in playground · 708b7bef
      Mitigate XSS vulnerabilities in the playground where AI-generated content
      is rendered without sanitization, allowing potential script injection via
      prompt injection attacks.
      
      MarkdownRenderer.jsx:
      - Replace dangerouslySetInnerHTML with a sandboxed iframe for HTML preview
      - Use sandbox="allow-same-origin" to block script execution while allowing
        CSS rendering and iframe height auto-sizing
      - Add SandboxedHtmlPreview component with automatic height adjustment
      
      CodeViewer.jsx:
      - Add escapeHtml() utility to encode HTML entities before rendering
      - Rewrite highlightJson() to process tokens iteratively, escaping each
        token and structural text before wrapping in syntax highlighting spans
      - Escape non-JSON and very-large content paths that previously bypassed
        sanitization
      - Update linkRegex to correctly match URLs containing & entities
      
      These changes only affect the playground (AI output rendering). Admin-
      configured content (home page, about page, footer, notices) remains
      unaffected as they use separate code paths and are within the trusted
      admin boundary.
      t0ng7u committed
  2. 05 Feb, 2026 12 commits
  3. 04 Feb, 2026 26 commits
  4. 03 Feb, 2026 1 commit