Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate and implement script tag prevention #519

Open
szczz opened this issue Dec 17, 2024 · 0 comments
Open

Investigate and implement script tag prevention #519

szczz opened this issue Dec 17, 2024 · 0 comments
Labels
Priority: High This task is high priority and should be tackled soon Storylines Viewer Work surrounding the Storylines Viewer that loads individual StoryRAMP products

Comments

@szczz
Copy link
Member

szczz commented Dec 17, 2024

Description

During the 12-17 Platform meeting, we decided that we didn't want to remove the ability for tags to be included in text panels, despite the expectation for custom styles to be added from the advanced editor. There are greater benefits to allowing this than there are realistic risks from users choosing to add their styles this way.

However, we shouldn't allow things like scripts tags to be included as this is a security issue.

Investigate whether script tags can be injected in storylines products, and if so we need to implement a fix on the storylines side to properly strip these.

Related issues

ramp4-pcar4/storylines-editor#423

@szczz szczz added Priority: High This task is high priority and should be tackled soon Storylines Viewer Work surrounding the Storylines Viewer that loads individual StoryRAMP products labels Dec 17, 2024
@szczz szczz changed the title Investigate and impelement script tag prevention Investigate and implement script tag prevention Dec 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Priority: High This task is high priority and should be tackled soon Storylines Viewer Work surrounding the Storylines Viewer that loads individual StoryRAMP products
Projects
None yet
Development

No branches or pull requests

1 participant