Commit 981faf2
committed
feat(backend): implement sanitization utilities for XSS prevention
chore(backend): update dependencies for security and performance
refactor(backend): replace DOMPurify with sanitize-html for sanitization
test(backend): add unit tests for sanitization utilities
fix(backend): update OAuth state cookie format in tests1 parent 4420743 commit 981faf2
File tree
9 files changed
+795
-697
lines changed- services/backend
- src
- routes/mcp/installations
- services
- utils
- tests/unit
- routes/auth
- utils
9 files changed
+795
-697
lines changedSome generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
41 | | - | |
42 | 41 | | |
43 | 42 | | |
44 | 43 | | |
| |||
60 | 59 | | |
61 | 60 | | |
62 | 61 | | |
| 62 | + | |
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| 76 | + | |
76 | 77 | | |
77 | 78 | | |
78 | 79 | | |
| |||
Lines changed: 6 additions & 19 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
| |||
70 | 71 | | |
71 | 72 | | |
72 | 73 | | |
73 | | - | |
74 | | - | |
| 74 | + | |
| 75 | + | |
75 | 76 | | |
76 | 77 | | |
77 | 78 | | |
78 | 79 | | |
79 | 80 | | |
80 | 81 | | |
81 | | - | |
| 82 | + | |
82 | 83 | | |
83 | 84 | | |
84 | 85 | | |
| |||
589 | 590 | | |
590 | 591 | | |
591 | 592 | | |
592 | | - | |
| 593 | + | |
593 | 594 | | |
594 | 595 | | |
595 | 596 | | |
| |||
604 | 605 | | |
605 | 606 | | |
606 | 607 | | |
607 | | - | |
608 | | - | |
609 | | - | |
610 | | - | |
611 | | - | |
612 | | - | |
613 | | - | |
614 | | - | |
615 | | - | |
616 | | - | |
617 | | - | |
618 | | - | |
619 | | - | |
620 | | - | |
621 | | - | |
| 608 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
59 | | - | |
60 | 14 | | |
61 | 15 | | |
62 | 16 | | |
| |||
351 | 305 | | |
352 | 306 | | |
353 | 307 | | |
354 | | - | |
355 | | - | |
356 | | - | |
357 | | - | |
358 | | - | |
359 | | - | |
360 | | - | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
361 | 311 | | |
362 | | - | |
| 312 | + | |
363 | 313 | | |
364 | 314 | | |
365 | 315 | | |
366 | 316 | | |
367 | 317 | | |
368 | | - | |
369 | | - | |
| 318 | + | |
| 319 | + | |
370 | 320 | | |
371 | | - | |
| 321 | + | |
372 | 322 | | |
373 | | - | |
| 323 | + | |
374 | 324 | | |
375 | | - | |
| 325 | + | |
376 | 326 | | |
377 | 327 | | |
378 | 328 | | |
379 | 329 | | |
380 | 330 | | |
381 | | - | |
382 | | - | |
383 | | - | |
384 | | - | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
385 | 335 | | |
386 | 336 | | |
387 | 337 | | |
388 | | - | |
| 338 | + | |
389 | 339 | | |
390 | | - | |
| 340 | + | |
391 | 341 | | |
392 | 342 | | |
393 | 343 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
3 | | - | |
4 | | - | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
| 1 | + | |
41 | 2 | | |
42 | 3 | | |
43 | 4 | | |
44 | 5 | | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
45 | 9 | | |
46 | 10 | | |
47 | 11 | | |
48 | 12 | | |
49 | 13 | | |
50 | 14 | | |
51 | 15 | | |
52 | | - | |
| 16 | + | |
53 | 17 | | |
54 | 18 | | |
55 | 19 | | |
56 | | - | |
| 20 | + | |
57 | 21 | | |
58 | 22 | | |
59 | 23 | | |
| |||
65 | 29 | | |
66 | 30 | | |
67 | 31 | | |
| 32 | + | |
| 33 | + | |
68 | 34 | | |
69 | 35 | | |
70 | 36 | | |
| |||
78 | 44 | | |
79 | 45 | | |
80 | 46 | | |
81 | | - | |
82 | | - | |
83 | | - | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | | - | |
93 | | - | |
94 | | - | |
95 | | - | |
96 | | - | |
97 | | - | |
98 | | - | |
99 | | - | |
100 | | - | |
101 | | - | |
102 | | - | |
103 | | - | |
104 | | - | |
| 47 | + | |
105 | 48 | | |
0 commit comments