Repository navigation
Releases: TonyMerlin/M2-ProductFinder
Release list
Version 2.1.4
v2.1.4
Security
Fix: Resolved GitHub CodeQL js/xss-through-dom warning within the frontend Product Finder.
Fix: Added strict validation for attribute set profile image URLs before assigning them to frontend <img> elements.
Fix: Restricted profile images to same-origin HTTP(S) URLs within /media/merlin_productfinder/, preventing untrusted URLs from being rendered.
Changed
Change: Refactored frontend image rendering to validate image URLs before assigning the src property.
Fix: Invalid image URLs are now safely ignored, preventing unsafe DOM injection while preserving existing functionality.
Fix: Replaced malformed em-dash characters in progressive AJAX status messages with Unicode escape sequences to prevent character encoding issues.
Version 2.1.3
Version 2.1.3
Security
- Resolved CodeQL warning
js/xss-through-domaffecting profile image previews within the admin Profile Builder (view/adminhtml/web/js/profiles.js). - Added strict validation for profile image URLs before assigning them to the preview
<img>element. - Profile image previews now only accept same-origin HTTP(S) URLs within
/media/merlin_productfinder/. - Applied the same validation to both existing profile images and newly uploaded images before rendering them in the admin UI.
Changed
- Switched profile image preview updates from jQuery
.attr('src', ...)to.prop('src', ...)after URL validation. - Improved upload error handling to provide clearer feedback when invalid image URLs are returned.
- Internal JavaScript hardening only.
- No functional or configuration changes for administrators.
Version 2.1.2
Security
- Resolved CodeQL warning
js/incomplete-sanitizationwithin the admin Profile Builder (view/adminhtml/web/js/profiles.js). - Removed dynamic CSS selector generation for attribute set lookups.
- Attribute set names are now resolved using direct DOM value comparison instead of escaped selector strings, eliminating the need for manual sanitisation and improving code robustness.
Changed
- Internal JavaScript refactoring only.
- No changes to functionality, configuration, or the administrator user experience.
Version 2.1.1
Fix: Fix form issue since adding configurable products.
Version 2.1.0
#v2.1.0
Add: Add configurable product support
Fix: Fix type error in results constructor
Version 2.0.6
Fix on/off switch to actually turn off the frontend form.
Version 2.0.5
Version 2.0.4
Fix: Element 'show_in_wysiwyg': This element is not expected.
Version 2.0.2
#v2.0.2
Fix: Currency symbol clean-up, encoding mismatch and a broken literal in JavaScript.
Add: Support multi select attributes
Add: default html values for pre and post form content
Version 2.0.1
Version 2.0.0
New: Refactor the admin attribute set wizard with a drag and drop interface for building out the product finder quickly.
Fix: Clean-up the frontend UX and results page
Fix: Clean-up the configuration page removing all legacy options.