Skip to content

fix(security): sanitize dynamic markup interpolations and validate external URLs (closes #214) - #218

Open
rupesh-kumar-sah wants to merge 2 commits into
SPulse-Org:mainfrom
rupesh-kumar-sah:fix/issue-214-xss-sanitization
Open

rupesh-kumar-sah wants to merge 2 commits into
SPulse-Org:mainfrom
rupesh-kumar-sah:fix/issue-214-xss-sanitization

Conversation

@rupesh-kumar-sah

Copy link
Copy Markdown

Description

This PR resolves #214 by closing the stored and DOM-based Cross-Site Scripting (XSS) attack vectors across frontend dynamic rendering paths.

Changes

  • Sanitization Engine (frontend/sanitize.js):
    • Implemented escapeHtml(str): safely converts &, <, >, ", and ' to standard HTML entities before template literal interpolation.
    • Implemented sanitizeUrl(url): strictly rejects dangerous URL schemes (javascript:, data:, vbscript:) and validates allowable web protocols (https://, /, #).
  • Dynamic Renderers Hardened:
    • frontend/script.js: Sanitized dynamic market metadata (market.category, market.title, market.detail, market.close), user positions (position.title, position.time, position.stake, position.returns), and validated explorer links (position.explorerUrl).
    • frontend/pages.js: Sanitized market search cards (m.category, m.title, m.close) and leaderboard identities (p.name, p.address).
  • Automated Regression Suite (tests/xss-sanitization.test.mjs):
    • Added unit test coverage verifying that hostile markup (e.g. <img src=x onerror="...">, <script>...</script>) and malicious URI schemes are neutralized.
    • Integrated into .github/workflows/ci.yml frontend verification pipeline.

Verification

  • node scripts/validate-frontend.mjs: Passed (3 HTML pages, 11 source files validated)
  • find frontend -type f -name '*.js' -print0 | xargs -0 -n1 node --check: Passed with 0 syntax errors
  • node --test tests/xss-sanitization.test.mjs: All 5 test suites passed 100%

Closes #214.

Muyideen-js and others added 2 commits September 12, 2026 14:50
…e-211-vendor-sdk-csp

fix(security): vendor stellar-sdk and freighter-api with strict CSP (closes SPulse-Org#211)
@vercel

vercel Bot commented Sep 17, 2026

Copy link
Copy Markdown

@rupesh-kumar-sah is attempting to deploy a commit to the Muyideen-jsx's projects Team on Vercel.

A member of the Team first needs to authorize it.

@netlify

netlify Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stellar-pulse ready!

Name Link
🔨 Latest commit b49723b
🔍 Latest deploy log https://app.netlify.com/projects/stellar-pulse/deploys/6aab9b263a39e00008d7ddcb
😎 Deploy Preview https://deploy-preview-218--stellar-pulse.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Any user can store arbitrary strings on chain that the frontend will render as HTML

2 participants