Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fio 7544 html sanitization issue #5559

Merged
merged 5 commits into from
Apr 16, 2024
Merged

Conversation

alexandraRamanenka
Copy link
Contributor

Link to Jira Ticket

https://formio.atlassian.net/browse/FIO-7544

Description

This PR was originally reverted due to stopping interpolation from working properly (#5418), but it seems that with sanitizer upgrade the issue was resolved and now sanitizer does not touch code inside {{}}. I added a test to confirm that.
We can't interpolate first and sanitize after that because for HTML component we use translateHTMLtemplate function that creates a div with HTML component's content to translate its text nodes, so if it's not sanitized, all teh code will be executed on that stage.

Dependencies

This PR depends on the following PRs from other Form.io modules: ...

How has this PR been tested?

Automated tests added both for the issue itself and for the interpolation

Checklist:

  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation (if applicable)
  • My changes generate no new warnings
  • My changes include tests that prove my fix is effective (or that my feature works as intended)
  • New and existing unit/integration tests pass locally with my changes
  • Any dependent changes have corresponding PRs that are listed above

@travist travist merged commit 0ffd33b into master Apr 16, 2024
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants