Skip to content

LocalJam v2026.09.033

Choose a tag to compare

@github-actions github-actions released this 05 Sep 07:35
Immutable release. Only release title and notes can be modified.

LocalJam v2026.09.033

Live Deployment & App Access

Commit Details

Subject: fix(security): remediate path traversal, CSP, DOM XSS, and add automated security tests
Date: 2026-09-05 00:35:31 -0700

Commit Message

  • Remediate SEC-01 path traversal in server.js by enforcing canonical root boundary checks on raw decoded URL paths.
  • Add SEC-02 Content-Security-Policy meta tag in index.html for hosted GitHub Pages environment.
  • Neutralize SEC-03 DOM XSS in station-modal.js by sanitizing homepageUrl and blocking javascript: and protocol-relative URIs.
  • Remediate SEC-04 & SEC-06 inline event handlers in radio-view.js, home-view.js, and playlists-view.js with semantic anchor links and event listeners.
  • Add centralized sanitization library in src/utils/sanitize.js providing full HTML entity escaping, URL sanitization, raster MIME allowlisting, and bounded text trimming.
  • Remediate SEC-07 unescaped error strings in router.js exception rendering view.
  • Remediate SEC-08 unvalidated MIME types in id3v2.js and flac.js metadata parsers with raster image allowlists.
  • Remediate SEC-09 custom station schema validation in stations.js by enforcing HTTPS protocol and URL parsing.
  • Add SEC-10 HTTP defense-in-depth security headers (CSP, nosniff, SAMEORIGIN, Permissions-Policy, COOP, CORP) and SEC-11 error masking in server.js.
  • Add comprehensive automated test suite in test/security.test.js with 100% pass across all 11 security findings.