Skip to content

fix: escape impersonation banner email - #855

Merged
shyim merged 1 commit into
mainfrom
codex/fix-stored-xss-in-impersonation-banner
Sep 30, 2026
Merged

shyim merged 1 commit into
mainfrom
codex/fix-stored-xss-in-impersonation-banner

Conversation

@shyim

@shyim shyim commented Sep 30, 2026

Copy link
Copy Markdown
Member

Motivation

  • Prevent stored XSS that could execute attacker-controlled HTML in the impersonation banner and steal the stashed admin bearer token.

Description

  • Replace the v-html sink in frontend/src/components/ImpersonationBanner.vue with Vue text interpolation to ensure the impersonated user's email is escaped.
  • Add a regression unit test frontend/src/components/ImpersonationBanner.spec.ts that injects a malicious HTML payload as the email and asserts it is rendered as literal text and does not create DOM elements.
  • Commit includes the two modified/added frontend files and a succinct test to prevent regressions.

Testing

  • Ran frontend lint and type checks with npm run lint and npm run tsc, which completed successfully for the frontend.
  • Ran format check with npm run format, which passed for the frontend files updated.
  • Ran the new unit test with npm run test:run -- src/components/ImpersonationBanner.spec.ts, which passed (1 test, 1 passed).
  • mise run lint could not fully complete because the installed golangci-lint was built with Go 1.24 while the project targets Go 1.26.1, preventing the API lint step from finishing.
  • mise run test could not complete API integration tests because Testcontainers require Docker/rootless Docker, which is unavailable in the current environment.

Codex Task

@shyim
shyim marked this pull request as ready for review September 30, 2026 11:22
@shyim
shyim merged commit d1aedf0 into main Sep 30, 2026
5 checks passed
@shyim
shyim deleted the codex/fix-stored-xss-in-impersonation-banner branch September 30, 2026 11:22
@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Fixes HTML injection in impersonation banner display.

The PR appears safe to merge.

Summary

The PR replaces HTML rendering of the impersonation banner translation with escaped Vue text interpolation and adds a regression test using an HTML-bearing email.

  • The changed rendering prevents that email from creating DOM elements in the banner.
  • No actionable issue was identified.

Reviews (1) · Last reviewed commit: "fix: escape impersonation banner email"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant