mirror of
https://github.com/dreamhunter2333/cloudflare_temp_email.git
synced 2026-09-07 00:17:12 +08:00
fix: sanitize mail content in reply/forward to prevent XSS (#857)
* fix: sanitize mail content in reply/forward to prevent XSS - Add DOMPurify to sanitize HTML email content (whitelist-based) - Add escapeHtml for plain text content (escape &<>"') - Guard mail.originalSource with fallback to empty string - Add jsdom for vitest DOM environment (DOMPurify requires DOM) - Add XSS regression tests (script tags, event handlers, HTML escape) - Add contentType assertion for empty message fallback case Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add XSS sanitization E2E screenshots Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: remove temporary screenshots from tree Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: normalize escapeHtml input and add forward text escape test - escapeHtml: convert input via String(str ?? '') to handle non-string values - Add test for plain text forward with special chars (<, &, >) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
372f7b4149
commit
0c337a1942
@@ -21,6 +21,7 @@
|
||||
- fix: |前端| 修复暗色主题下邮件内容文字看不清的问题,优化纯文本邮件和 Shadow DOM 渲染的暗色模式样式
|
||||
- docs: |文档| 新增 Admin 删除邮件、删除邮箱地址、清空收件箱、清空发件箱 API 文档
|
||||
- fix: |前端| 修复回复 HTML 格式邮件时丢失原邮件 HTML 内容的问题,优先使用 HTML 原文而非纯文本
|
||||
- fix: |安全| 修复回复/转发邮件时的 XSS 风险,使用 DOMPurify 对 HTML 内容进行白名单消毒,对纯文本内容进行 HTML 转义
|
||||
|
||||
### Improvements
|
||||
|
||||
|
||||
Reference in New Issue
Block a user