fix(editor): Prevent XSS in node-issues tooltip (#9490)

This commit is contained in:
कारतोफ्फेलस्क्रिप्ट™ 2024-05-22 18:40:42 +02:00 committed by GitHub
parent 0deb7d0fcc
commit 301e846cf6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -180,6 +180,7 @@
<script lang="ts">
import { defineComponent } from 'vue';
import { mapStores } from 'pinia';
import xss from 'xss';
import { useStorage } from '@/composables/useStorage';
import {
CUSTOM_API_CALL_KEY,
@ -467,11 +468,9 @@ export default defineComponent({
if (nodeExecutionRunData) {
nodeExecutionRunData.forEach((executionRunData) => {
if (executionRunData?.error) {
issues.push(
`${executionRunData.error.message}${
executionRunData.error.description ? ` (${executionRunData.error.description})` : ''
}`,
);
const { message, description } = executionRunData.error;
const issue = `${message}${description ? ` (${description})` : ''}`;
issues.push(xss(issue));
}
});
}