LocalJam v2026.09.033
Immutable
release. Only release title and notes can be modified.
LocalJam v2026.09.033
Live Deployment & App Access
- π Web App: https://varun.khaneja.org/LocalJam/
- π·οΈ Release Tag: v2026.09.033
- π¦ Repository Commit: 721bc8f6936e1a68bb3f93939bd8bcb04bdb9aec
Commit Details
Subject: fix(security): remediate path traversal, CSP, DOM XSS, and add automated security tests
Date: 2026-09-05 00:35:31 -0700
Commit Message
- Remediate SEC-01 path traversal in server.js by enforcing canonical root boundary checks on raw decoded URL paths.
- Add SEC-02 Content-Security-Policy meta tag in index.html for hosted GitHub Pages environment.
- Neutralize SEC-03 DOM XSS in station-modal.js by sanitizing homepageUrl and blocking javascript: and protocol-relative URIs.
- Remediate SEC-04 & SEC-06 inline event handlers in radio-view.js, home-view.js, and playlists-view.js with semantic anchor links and event listeners.
- Add centralized sanitization library in src/utils/sanitize.js providing full HTML entity escaping, URL sanitization, raster MIME allowlisting, and bounded text trimming.
- Remediate SEC-07 unescaped error strings in router.js exception rendering view.
- Remediate SEC-08 unvalidated MIME types in id3v2.js and flac.js metadata parsers with raster image allowlists.
- Remediate SEC-09 custom station schema validation in stations.js by enforcing HTTPS protocol and URL parsing.
- Add SEC-10 HTTP defense-in-depth security headers (CSP, nosniff, SAMEORIGIN, Permissions-Policy, COOP, CORP) and SEC-11 error masking in server.js.
- Add comprehensive automated test suite in test/security.test.js with 100% pass across all 11 security findings.