From 27711b7c21a8545594fa9d548925d599bb91a237 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Tue, 6 Oct 2026 20:58:45 +0200 Subject: [PATCH] chore(scripts): allow the sanitized markdown preview binding in raw-HTML gates - check-phase10, 12.1, 12.2 and 14.2.1 drop only the exact MarkdownField.vue line binding sanitizedHtml (server-rendered by cabana.RenderMarkdown); every other raw-HTML sink is still refused --- scripts/check-phase10.sh | 4 +++- scripts/check-phase12.1.sh | 4 +++- scripts/check-phase12.2.sh | 4 +++- scripts/check-phase14.2.1.sh | 4 +++- 4 files changed, 12 insertions(+), 4 deletions(-) diff --git a/scripts/check-phase10.sh b/scripts/check-phase10.sh index 5ec61fe..dc4d7dd 100755 --- a/scripts/check-phase10.sh +++ b/scripts/check-phase10.sh @@ -352,7 +352,9 @@ hygiene_checks() { admin/src admin/tests admin/openapi modules/boardwalk modules/cabana modules/phrasebook 2>/dev/null || true)" [[ -z "$hits" ]] || fail "application names in the framework: $hits" # Plugin and server strings are rendered as text only. - hits="$(cd "$tree" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null || true)" + # The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused. + hits="$(cd "$tree" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null | + grep -vE '^admin/src/components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)" [[ -z "$hits" ]] || fail "raw-HTML directive in admin/src: $hits" # All HTTP goes through the typed openapi-fetch client. hits="$(cd "$tree" && grep -rnE '(^|[^A-Za-z0-9_.])fetch\(|XMLHttpRequest\(|axios' admin/src --include='*.ts' --include='*.vue' 2>/dev/null | diff --git a/scripts/check-phase12.1.sh b/scripts/check-phase12.1.sh index 7d49039..f4f3ad4 100755 --- a/scripts/check-phase12.1.sh +++ b/scripts/check-phase12.1.sh @@ -445,7 +445,9 @@ run_hygiene() { echo "refuse: hygiene: the test fixture plugin is referenced by production code: $hits" >&2 bad=1 fi - hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null || true)" + # The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused. + hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null | + grep -vE '^admin/src/components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)" if [[ -n "$hits" ]]; then echo "refuse: hygiene: raw-HTML sink in admin/src: $hits" >&2 bad=1 diff --git a/scripts/check-phase12.2.sh b/scripts/check-phase12.2.sh index ce6cd80..e75b986 100755 --- a/scripts/check-phase12.2.sh +++ b/scripts/check-phase12.2.sh @@ -271,7 +271,9 @@ run_hygiene() { echo "refuse: hygiene: a session key in a URL: $hits" >&2 bad=1 fi - hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null || true)" + # The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused. + hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null | + grep -vE '^admin/src/components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)" if [[ -n "$hits" ]]; then echo "refuse: hygiene: raw-HTML sink in admin/src: $hits" >&2 bad=1 diff --git a/scripts/check-phase14.2.1.sh b/scripts/check-phase14.2.1.sh index 4bda293..5ee7ff7 100755 --- a/scripts/check-phase14.2.1.sh +++ b/scripts/check-phase14.2.1.sh @@ -323,7 +323,9 @@ run_forbidden() { echo "refuse: consuming-application name in framework docs: $hits" >&2 bad=1 fi - hits="$(cd "$ROOT/admin/src" && grep -RInE 'v-html=|innerHTML|outerHTML|insertAdjacentHTML' . || true)" + # The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused. + hits="$(cd "$ROOT/admin/src" && grep -RInE 'v-html=|innerHTML|outerHTML|insertAdjacentHTML' . | + grep -vE '^\./components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)" if [[ -n "$hits" ]]; then echo "refuse: raw-HTML sink in admin/src: $hits" >&2 bad=1