chore(scripts): allow the sanitized markdown preview binding in raw-HTML gates

- check-phase10, 12.1, 12.2 and 14.2.1 drop only the exact
  MarkdownField.vue line binding sanitizedHtml (server-rendered by
  cabana.RenderMarkdown); every other raw-HTML sink is still refused
This commit is contained in:
Jakub Zych
2026-10-06 20:58:45 +02:00
parent a0116dfbb9
commit 27711b7c21
4 changed files with 12 additions and 4 deletions

View File

@@ -445,7 +445,9 @@ run_hygiene() {
echo "refuse: hygiene: the test fixture plugin is referenced by production code: $hits" >&2
bad=1
fi
hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null || true)"
# The markdown preview binds only the HTML POST /markdown/preview answers (cabana.RenderMarkdown); every other raw-HTML sink is still refused.
hits="$(cd "$ROOT" && grep -rnE 'v-html|innerHTML|outerHTML|insertAdjacentHTML' admin/src 2>/dev/null |
grep -vE '^admin/src/components/form/fields/MarkdownField\.vue:[0-9]+:[[:space:]]*v-html="sanitizedHtml"[[:space:]]*$' || true)"
if [[ -n "$hits" ]]; then
echo "refuse: hygiene: raw-HTML sink in admin/src: $hits" >&2
bad=1