CB-4743 adds html sanitizer (#2420)

* CB-4743 adds html sanitizer

* CB-4743 adds license to sanitizeHtml

* CB-4743 do not use sanitize to purify the json line data

* CB-4743 fix: toSafeHtmlString test correct cases

---------

Co-authored-by: s.teleshev <s.teleshev@mu.se>
Co-authored-by: mr-anton-t <42037741+mr-anton-t@users.noreply.github.com>
This commit is contained in:
sergeyteleshev
2024-03-05 22:14:35 +03:00
committed by GitHub
co-authored by s.teleshev mr-anton-t
parent 23328e7ea4
commit 9934ed9787
3 changed files with 43 additions and 0 deletions
+1
View File
@@ -77,3 +77,4 @@ export * from './removeLineBreak';
export * from './replaceSubstring';
export * from './formatNumber';
export * from './withTimestamp';
export * from './toSafeHtmlString';
@@ -0,0 +1,28 @@
/*
* CloudBeaver - Cloud Database Manager
* Copyright (C) 2020-2024 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0.
* you may not use this file except in compliance with the License.
*/
import { toSafeHtmlString } from './toSafeHtmlString';
describe('toSafeHtmlString', () => {
it('should make html string safe', () => {
const input = '<script>alert("some unsafe action")</script>';
const output = toSafeHtmlString(input);
expect(output).toBe('&lt;script&gt;alert("some unsafe action")&lt;/script&gt;');
});
it('should return empty string', () => {
const input = '';
const output = toSafeHtmlString(input);
expect(output).toBe('');
});
it('should return the same string', () => {
const input = 'some safe string';
const output = toSafeHtmlString(input);
expect(output).toBe(input);
});
});
@@ -0,0 +1,14 @@
/*
* CloudBeaver - Cloud Database Manager
* Copyright (C) 2020-2024 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0.
* you may not use this file except in compliance with the License.
*/
export function toSafeHtmlString(dirty: string): string {
const el = document.createElement('div');
el.innerText = el.textContent = dirty;
dirty = el.innerHTML;
return dirty;
}