Skip to content

Conversation

@ekuboo100
Copy link

@ekuboo100 ekuboo100 commented Feb 28, 2025

Ticket 🎟️ #13419

To fix the problem, we need to ensure that the value assigned to innerHTML is properly escaped to prevent any potential XSS attacks. The best way to do this is to use textContent instead of innerHTML, as textContent will treat the value as plain text rather than HTML, thus preventing any HTML or JavaScript from being executed.

Launch Checklist

  • Make sure the PR title is descriptive and preferably reflects the change from the user's perspective.
  • Add additional detail and context in the PR description (with screenshots/videos if there are visual changes).
  • Manually test the debug page.
  • Write tests for all new functionality and make sure the CI checks pass.
  • Document any changes to public APIs.
  • Post benchmark scores if the change could affect performance.
  • Tag @mapbox/map-design-team @mapbox/static-apis if this PR includes style spec API or visual changes.
  • Tag @mapbox/gl-native if this PR includes shader changes or needs a native port.

@ekuboo100 ekuboo100 requested a review from a team as a code owner February 28, 2025 02:25
@CLAassistant
Copy link

CLAassistant commented Feb 28, 2025

CLA assistant check
All committers have signed the CLA.

@stepankuzmin
Copy link
Contributor

Hi @odaysec,

The debug/globe-fill-extrusion.html page is used only for development and is not part of the GL JS package, so it is not considered an issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants