Skip to content

DEVELOP-471-1 security review changes#9

Merged
cornu-ammonis merged 3 commits intomasterfrom
DEVELOP-471-1-security-review-changes
Apr 27, 2021
Merged

DEVELOP-471-1 security review changes#9
cornu-ammonis merged 3 commits intomasterfrom
DEVELOP-471-1-security-review-changes

Conversation

@cornu-ammonis
Copy link
Contributor

@cornu-ammonis cornu-ammonis commented Apr 27, 2021

Aha! requirement

we should be mindful of links as an xss vector. a user could update the extension field values for pr url etc to be "javascript:alert(1)" etc which will trigger xss on click for a standard react <a tag. in chrome this doesnt work when the <a tag is target="_blank" but in safari it does work. I've created https://big.aha.io/features/DEVOPS-626 to track a longer term solution to this.

@cornu-ammonis cornu-ammonis requested a review from jemmyw April 27, 2021 23:05
@cornu-ammonis cornu-ammonis merged commit e47bed8 into master Apr 27, 2021
@cornu-ammonis cornu-ammonis deleted the DEVELOP-471-1-security-review-changes branch April 27, 2021 23:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants