Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes formatted description in email + sanitize html everywhere #7928

Merged
merged 10 commits into from
Mar 28, 2023

Conversation

CarinaWolli
Copy link
Member

@CarinaWolli CarinaWolli commented Mar 24, 2023

What does this PR do?

  • Adds formatting to event-type description in email:
  • Sanitize all description and bio set with dangerouslySetInnerHTML with sanitize-html

@CarinaWolli CarinaWolli requested review from a team March 24, 2023 11:06
@vercel
Copy link

vercel bot commented Mar 24, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated
cal ✅ Ready (Inspect) Visit Preview 💬 Add your feedback Mar 28, 2023 at 9:33AM (UTC)
dhe ❌ Failed (Inspect) Mar 28, 2023 at 9:33AM (UTC)
ui ✅ Ready (Inspect) Visit Preview 💬 Add your feedback Mar 28, 2023 at 9:33AM (UTC)

@@ -21,7 +22,6 @@ if (process.env.NODE_ENV !== "production") {
}
// If any changed on middleware server restart is required
bookingReferenceMiddleware(prisma);
eventTypeDescriptionParseAndSanitizeMiddleware(prisma);
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@zomars & @emrysal I removed that middleware now as descriptionAsSafeHTML is coming from all parts of my code already. Any objections to this?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@zomars what do you think about removing the middleware for sanitizing the event type description?

@github-actions
Copy link
Contributor

github-actions bot commented Mar 24, 2023

📦 Next.js Bundle Analysis

This analysis was generated by the next.js bundle analysis action 🤖

🎉 Global Bundle Size Decreased

Page Size (compressed)
global 233.24 KB (-17 B)
Details

The global bundle is the javascript bundle that loads alongside every page. It is in its own category because its impact is much higher - an increase to its size means that every page on your website loads slower, and a decrease means every page loads faster.

Any third party scripts you have added directly to your app using the <script> tag are not accounted for in this analysis

If you want further insight into what is behind the changes, give @next/bundle-analyzer a try!

Sixty-seven Pages Changed Size

The following pages changed size from the code in this PR compared to its base branch:

Page Size (compressed) First Load % of Budget (350 KB)
/404 8.36 KB 241.6 KB 69.03% (+/- <0.01%)
/[user] 70.15 KB 303.39 KB 86.68% (🟢 -9.50%)
/[user]/[type] 91.86 KB 325.1 KB 92.88% (🟡 +0.01%)
/[user]/[type]/embed 91.88 KB 325.12 KB 92.89% (+/- <0.01%)
/[user]/book 183.46 KB 416.69 KB 119.06% (+/- <0.01%)
/[user]/embed 70.22 KB 303.46 KB 86.70% (🟢 -9.50%)
/apps 167.17 KB 400.41 KB 114.40% (+/- <0.01%)
/apps/[slug] 190.89 KB 424.13 KB 121.18% (+/- <0.01%)
/apps/[slug]/[...pages] 392.29 KB 625.53 KB 178.72% (+/- <0.01%)
/apps/categories 152.07 KB 385.31 KB 110.09% (+/- <0.01%)
/apps/categories/[category] 155.94 KB 389.18 KB 111.19% (+/- <0.01%)
/apps/installed/[category] 197.04 KB 430.28 KB 122.94% (+/- <0.01%)
/auth/error 19.24 KB 252.48 KB 72.14% (+/- <0.01%)
/auth/forgot-password 25.63 KB 258.87 KB 73.96% (+/- <0.01%)
/auth/forgot-password/[id] 32.83 KB 266.07 KB 76.02% (+/- <0.01%)
/auth/login 40.1 KB 273.34 KB 78.10% (+/- <0.01%)
/auth/logout 7.56 KB 240.8 KB 68.80% (+/- <0.01%)
/availability 155.38 KB 388.62 KB 111.03% (+/- <0.01%)
/availability/[schedule] 272.14 KB 505.38 KB 144.39% (+/- <0.01%)
/availability/troubleshoot 152.76 KB 386 KB 110.29% (+/- <0.01%)
/booking/[uid] 123.57 KB 356.81 KB 101.94% (+/- <0.01%)
/bookings/[status] 272.38 KB 505.62 KB 144.46% (+/- <0.01%)
/d/[link]/[slug] 91.5 KB 324.74 KB 92.78% (+/- <0.01%)
/d/[link]/[slug]/embed 91.54 KB 324.78 KB 92.79% (+/- <0.01%)
/d/[link]/book 183.11 KB 416.35 KB 118.96% (+/- <0.01%)
/event-types 349.25 KB 582.49 KB 166.43% (🟢 -0.02%)
/event-types/[type] 382.82 KB 616.06 KB 176.02% (🟢 -0.02%)
/getting-started/[[...step]] 302.97 KB 536.21 KB 153.20% (🟢 -0.02%)
/insights 386.24 KB 619.48 KB 176.99% (+/- <0.01%)
/more 151.7 KB 384.94 KB 109.98% (+/- <0.01%)
/settings/admin 157.15 KB 390.39 KB 111.54% (+/- <0.01%)
/settings/admin/apps 165.84 KB 399.08 KB 114.02% (+/- <0.01%)
/settings/admin/apps/[category] 165.82 KB 399.06 KB 114.02% (+/- <0.01%)
/settings/admin/flags 160.05 KB 393.29 KB 112.37% (+/- <0.01%)
/settings/admin/impersonation 157.44 KB 390.68 KB 111.62% (+/- <0.01%)
/settings/billing 157.27 KB 390.5 KB 111.57% (+/- <0.01%)
/settings/developer/api-keys 186.42 KB 419.66 KB 119.90% (+/- <0.01%)
/settings/developer/webhooks 159.76 KB 393 KB 112.28% (+/- <0.01%)
/settings/developer/webhooks/[id] 190.61 KB 423.85 KB 121.10% (+/- <0.01%)
/settings/developer/webhooks/new 190.47 KB 423.71 KB 121.06% (+/- <0.01%)
/settings/my-account/appearance 171.23 KB 404.47 KB 115.56% (+/- <0.01%)
/settings/my-account/calendars 191.45 KB 424.69 KB 121.34% (+/- <0.01%)
/settings/my-account/conferencing 163.03 KB 396.27 KB 113.22% (+/- <0.01%)
/settings/my-account/general 266.42 KB 499.66 KB 142.76% (+/- <0.01%)
/settings/my-account/profile 274.24 KB 507.48 KB 144.99% (🟢 -0.02%)
/settings/security/impersonation 159.31 KB 392.54 KB 112.16% (+/- <0.01%)
/settings/security/password 192.6 KB 425.84 KB 121.67% (+/- <0.01%)
/settings/security/sso 167 KB 400.24 KB 114.35% (+/- <0.01%)
/settings/security/two-factor-auth 161.76 KB 395 KB 112.86% (+/- <0.01%)
/settings/teams 156.9 KB 390.14 KB 111.47% (+/- <0.01%)
/settings/teams/[id]/appearance 171.25 KB 404.49 KB 115.57% (+/- <0.01%)
/settings/teams/[id]/billing 157.13 KB 390.37 KB 111.54% (🟢 -0.01%)
/settings/teams/[id]/members 297.14 KB 530.38 KB 151.54% (+/- <0.01%)
/settings/teams/[id]/profile 269.45 KB 502.69 KB 143.63% (🟢 -0.02%)
/settings/teams/[id]/sso 167.09 KB 400.33 KB 114.38% (+/- <0.01%)
/signup 25.5 KB 258.74 KB 73.92% (+/- <0.01%)
/team/[slug] 72.62 KB 305.86 KB 87.39% (🟢 -9.50%)
/team/[slug]/[type] 91.51 KB 324.75 KB 92.78% (🟡 +0.01%)
/team/[slug]/[type]/embed 91.54 KB 324.78 KB 92.79% (+/- <0.01%)
/team/[slug]/book 183.11 KB 416.35 KB 118.96% (+/- <0.01%)
/team/[slug]/embed 72.68 KB 305.92 KB 87.41% (🟢 -9.51%)
/teams 151.92 KB 385.15 KB 110.04% (+/- <0.01%)
/video/meeting-ended/[uid] 14.67 KB 247.9 KB 70.83% (+/- <0.01%)
/video/meeting-not-started/[uid] 14.3 KB 247.54 KB 70.72% (+/- <0.01%)
/video/no-meeting-found 6.6 KB 239.84 KB 68.53% (+/- <0.01%)
/workflows 164.81 KB 398.05 KB 113.73% (+/- <0.01%)
/workflows/[workflow] 294.03 KB 527.26 KB 150.65% (+/- <0.01%)
Details

Only the gzipped size is provided here based on an expert tip.

First Load is the size of the global bundle plus the bundle for the individual page. If a user were to show up to your website and land on a given page, the first load size represents the amount of javascript that user would need to download. If next/link is used, subsequent page loads would only need to download that page's bundle (the number in the "Size" column), since the global bundle has already been downloaded.

Any third party scripts you have added directly to your app using the <script> tag are not accounted for in this analysis

The "Budget %" column shows what percentage of your performance budget the First Load total takes up. For example, if your budget was 100kb, and a given page's first load size was 10kb, it would be 10% of your budget. You can also see how much this has increased or decreased compared to the base branch of your PR. If this percentage has increased by 20% or more, there will be a red status indicator applied, indicating that special attention should be given to this. If you see "+/- <0.01%" it means that there was a change in bundle size, but it is a trivial enough amount that it can be ignored.

@CarinaWolli CarinaWolli changed the title Use santize-html for sanitizing bio and event type description Fixes formatted description in email + sanitize html everywhere Mar 24, 2023
@deploysentinel
Copy link

deploysentinel bot commented Mar 24, 2023

No failed tests 🎉

Copy link
Contributor

@emrysal emrysal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, not a change we can't come back from and it works.

@emrysal emrysal enabled auto-merge (squash) March 28, 2023 09:17
@socket-security
Copy link

New dependency changes detected. Learn more about Socket for GitHub ↗︎

👍 No new dependency issues detected in pull request

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

Pull request alert summary
Issue Status
Install scripts ✅ 0 issues
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues

📊 Modified Dependency Overview:

➕ Added Package Capability Access +/- Transitive Count Publisher
@types/sanitize-html@2.9.0 None +4 types
sanitize-html@2.10.0 None +5 boutell

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
core area: core, team members only
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants