Skip to content

fix(markdown): sanitize rendered markdown on experiment and publication pages - #726

Merged
bencap merged 1 commit into
release-2026.2.4.2from
bugfix/bencap/sanitize-markdown-views
Sep 28, 2026
Merged

bencap merged 1 commit into
release-2026.2.4.2from
bugfix/bencap/sanitize-markdown-views

Conversation

@bencap

@bencap bencap commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

Summary

ExperimentView and PublicationIdentifierView rendered abstracts and methods with raw marked output. Both now go through markdownToHtml, which sanitizes with DOMPurify. A new no-restricted-imports lint rule blocks importing marked anywhere except lib/form-helpers, so new views can't skip sanitization.

…on pages

ExperimentView and PublicationIdentifierView rendered abstracts and methods
with raw marked output. Route both through markdownToHtml, which sanitizes
with DOMPurify, and restrict direct imports of marked to lib/form-helpers so
new views can't bypass sanitization.
@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 10.274%. remained the same — bugfix/bencap/sanitize-markdown-views into release-2026.2.4.2

@bencap
bencap merged commit a9fb172 into release-2026.2.4.2 Sep 28, 2026
1 check passed
@bencap bencap mentioned this pull request Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants