Skip to content

Potential fix for code scanning alert no. 6: DOM text reinterpreted as HTML - #7

Merged
tonytech83 merged 3 commits into
mainfrom
alert-autofix-6
Aug 28, 2026
Merged

tonytech83 merged 3 commits into
mainfrom
alert-autofix-6

Conversation

@tonytech83

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/tonytech83/Inventory/security/code-scanning/6

General fix: never inject untrusted values via HTML string concatenation (.append('<tag>' + value + '</tag>')). Instead, create elements with jQuery/DOM APIs, set .text() for visible text, and set attributes via .attr() after minimal protocol/format checks where relevant.

Best fix here (without changing functionality): in staticfiles/js/supplier-crud.js, replace line 225 HTML-string append with safe node creation:

  • Create a <p> container.
  • Create an <a> element.
  • Set anchor text using .text(supplier.email || '') (safe escaping).
  • Set href using .attr('href', 'mailto:' + emailValue) after coercing to string.
  • Append text node "Email: " and the anchor to <p>, then append <p> to card.

This preserves rendered output while preventing HTML interpretation of supplier.email.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…s HTML

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread staticfiles/js/supplier-crud.js Fixed
…ed as HTML'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@tonytech83 tonytech83 self-assigned this Aug 28, 2026
@tonytech83
tonytech83 marked this pull request as ready for review August 28, 2026 17:59
@tonytech83
tonytech83 merged commit e147d91 into main Aug 28, 2026
4 checks passed
@tonytech83
tonytech83 deleted the alert-autofix-6 branch August 28, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants