Commit 7280217
fix(security): sanitize traffic-source values against scanner-injected payloads (#307)
* fix(security): sanitize traffic-source values against scanner-injected payloads
Vulnerability scanners (Acunetix and friends) crawl customer sites
injecting XSS probes like javascript:domxssExecutionSink(...) and
<script>alert(1)</script> into every query parameter. The SDK captured
those verbatim as utm_*/click-id/ref values, persisted them as sticky
session traffic sources, and polluted attribution reporting.
Validate each field class with the tightest rule its legitimate
production values allow:
- click IDs: strict token allowlist ^[A-Za-z0-9._-]{1,255}$
- ref: strict token allowlist ^[A-Za-z0-9._-]{1,64}$ (>99.5% of
production values conform; the rest are scanner payloads, mangled
encodings, or URLs glued to codes)
- utm_*: free-form, but reject markup/quote chars, dangerous scheme
prefixes, control/zero-width/replacement chars, and >255 chars
Sanitization runs on both the fresh URL extraction and the stored
session replay, so values poisoned by a pre-fix SDK are flushed too.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* test: expand traffic-source sanitization coverage
Adds empty-input and whitespace cases per sanitizer, non-ASCII ref
rejection, tab/newline/RTL-override/BOM UTM cases, and integration
coverage for referral.pathPattern / custom referral.queryParams
extraction plus the stored-value fallback when a fresh value is
poisoned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>1 parent e109171 commit 7280217
3 files changed
Lines changed: 517 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| 38 | + | |
38 | 39 | | |
39 | 40 | | |
40 | 41 | | |
| |||
268 | 269 | | |
269 | 270 | | |
270 | 271 | | |
271 | | - | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
272 | 276 | | |
273 | 277 | | |
274 | 278 | | |
275 | 279 | | |
276 | | - | |
| 280 | + | |
277 | 281 | | |
278 | 282 | | |
279 | 283 | | |
280 | | - | |
281 | | - | |
282 | | - | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
283 | 290 | | |
284 | 291 | | |
285 | 292 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
0 commit comments