🔒 fix: secure JSON stringification for application/ld+json tags to prevent XSS#24
🔒 fix: secure JSON stringification for application/ld+json tags to prevent XSS#24lsb11 wants to merge 2 commits into
Conversation
Creates a `safeJsonStringify` utility that replaces HTML control characters (`<`, `>`, `&`) with unicode escapes, and refactors all instances of `<script type="application/ld+json" set:html={JSON.stringify(s)} />` to use this utility.
Co-authored-by: lsb11 <269203137+lsb11@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Deploying stackarchitect2 with
|
| Latest commit: |
bd494b9
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://6660e8b6.stackarchitect2.pages.dev |
| Branch Preview URL: | https://fix-xss-json-stringify-83821.stackarchitect2.pages.dev |
Creates a `safeJsonStringify` utility that safely replaces HTML control characters (`<`, `>`, `&`) with unicode escapes, handling `undefined` gracefully. It also refactors all instances of `<script type="application/ld+json" set:html={JSON.stringify(s)} />` to use this safe utility to mitigate XSS risks.
Co-authored-by: lsb11 <269203137+lsb11@users.noreply.github.com>
🎯 What: The vulnerability fixed is Cross-Site Scripting (XSS) via
⚠️ Risk: If a JSON-LD schema contained HTML control characters (e.g., closing script tags like
set:htmlwithJSON.stringifywithin Astro<script type="application/ld+json">tags.</script>),JSON.stringifywould not escape them, potentially allowing an attacker to break out of the JSON block and inject malicious scripts.🛡️ Solution: Implemented
src/utils/safeJson.tsexportingsafeJsonStringify, which serializes JSON and subsequently replaces<,>, and&with their Unicode equivalents. Replaced all rawJSON.stringifycalls withinset:htmlforapplication/ld+jsontags across the codebase with this secure utility function. Added optional chaining to handle edge cases whereJSON.stringifyreturns undefined.PR created automatically by Jules for task 8382148263053952731 started by @lsb11