Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deletion of the HtmlFieldDescription function #3129

Merged
merged 1 commit into from
Mar 21, 2023

Conversation

ordabach
Copy link
Contributor

@ordabach ordabach commented Mar 21, 2023

What does this PR do?

Related to #3081.

Deletion of the HtmlFieldDescription function and its usages due to XSS vulnerability.

PR Checklist

  • Have you added an explanation of what your changes do and why you'd like to include them?
  • Is the TravisCI build passing?
  • Was the CHANGELOG.md updated to reflect the changes?
  • Was the documentation framework updated to reflect the changes?
  • Have you checked that you haven't introduced any duplicate code?

Testing Checklist

  • Added relevant unit tests?
  • Do all unit tests pass?
  • Do all end-to-end tests pass?
  • Any other testing performed?

    Tested by {Running the Monkey locally with relevant config/running Island/...}

  • If applicable, add screenshots or log transcripts of the feature working

@codecov
Copy link

codecov bot commented Mar 21, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (d4e8224) 71.75% compared to head (20bb67d) 71.75%.

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #3129   +/-   ##
========================================
  Coverage    71.75%   71.75%           
========================================
  Files          449      449           
  Lines        12827    12827           
========================================
  Hits          9204     9204           
  Misses        3623     3623           

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report in Codecov by Sentry.
📢 Do you have feedback about the report comment? Let us know in this issue.

@ordabach ordabach force-pushed the 3081-delete-html-field-description branch from 3e9a9c3 to 20bb67d Compare March 21, 2023 12:52
Copy link
Contributor

@ilija-lazoroski ilija-lazoroski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

GJ!

@@ -332,7 +331,6 @@ class ConfigurePageComponent extends AuthComponent {
selectedSection: this.state.selectedSection
})
formProperties['schema'] = displayedSchema
formProperties['fields'] = {DescriptionField: HtmlFieldDescription};
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't needed at all anymore? How does this affect the configuration page?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Currently, nothing is passed to this property so it doesn't affect anything.
If a need to render dangerous html will be raised in the future we'll create a better solution.

@mssalvatore mssalvatore merged commit fa7e27e into develop Mar 21, 2023
@mssalvatore mssalvatore deleted the 3081-delete-html-field-description branch March 21, 2023 18:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants