You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Security: a person's name could execute JavaScript in the web UI. Captions were
spliced into a single-quoted JS string inside an onclick attribute. The HTML escaper
does not escape apostrophes — and even if it did, the browser decodes them before the JS
parser runs — so a name like O'Brien, or a camera name from Frigate containing one,
terminated the string and ran arbitrary script. It affected four places: the history
card, the unknown queue (twice, fed by Frigate camera names) and the person cards. All of
them now pass the value through a data- attribute, where escaping is correct for the
context. Found while reviewing this release; it predates it.
The history shows one row per event and named person again (unknown faces keep one row
each — several strangers in a single frame all carry that label, and merging them would
swap their pictures against each other). It is titled "What FaceID
reported", but only the first match per person and event is ever reported — the announced set suppresses the rest. Every further row therefore claimed a notification
that never happened, and pushed genuine older entries out: 27 such rows out of 200 slots
on the reference instance, so the history reached 13% less far back than it should.
Later matches are not discarded, they improve the row. Checking the stored crops
first showed why that matters: all ten sampled duplicate pairs held different pictures,
sometimes drastically so — 8 KB against 94 KB of the same person, a distant crop against
a close one. Those later pictures are exactly what makes a wrong recognition checkable.
So a later match now improves the existing row instead of adding one: it replaces the
picture when its score is higher, and the card shows "best view 0.687" beside the
reported score. Independently of that, the first match that is actually published takes
over the row's score and timestamp even when it scores lower — it is the one somebody
received, and the card is headed "What FaceID reported".
Picture and embedding are always replaced together. Keeping them apart would let the
"was wrong" analysis run on a different face than the row displays.