Skip to content

Potential fix for code scanning alert no. 5: DOM text reinterpreted as HTML - #8

Merged
tonytech83 merged 2 commits into
mainfrom
alert-autofix-5
Aug 28, 2026
Merged

tonytech83 merged 2 commits into
mainfrom
alert-autofix-5

Conversation

@tonytech83

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/tonytech83/Inventory/security/code-scanning/5

The safest fix is to stop building HTML with string concatenation for untrusted values and instead build DOM nodes with text setters (.text() / textContent) and safe attribute setters (.attr()), which do not interpret user data as HTML.

Best single approach here:

  • In staticfiles/js/supplier-crud.js, inside the cards rendering loop (lines 220–225 region), replace each card.append('<...'+ value + '...</...>') with element creation via jQuery and .text(...).
  • For the email link, create <a> separately, set href using .attr('href', 'mailto:' + supplier.email), and set visible text with .text(supplier.email).
  • Keep behavior unchanged (same displayed content and click handling), only change construction method to avoid HTML interpretation.

No new imports or dependencies are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…s HTML

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread staticfiles/js/supplier-crud.js Fixed
…ed as HTML'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@tonytech83 tonytech83 self-assigned this Aug 28, 2026
@tonytech83
tonytech83 marked this pull request as ready for review August 28, 2026 17:56
@tonytech83
tonytech83 merged commit 8c62bce into main Aug 28, 2026
4 checks passed
@tonytech83
tonytech83 deleted the alert-autofix-5 branch August 28, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants