Security: - Disable SSL verification only in development (lib/req.js) - Wrap all JSON.parse(cookie) calls in try-catch via safeJsonParse utility - Sanitize dangerouslySetInnerHTML in blog/clinic with sanitizeHtml utility - Fix open redirect in payment page — validate URL origin before redirect - Fix cookie cleanup on 401 — use js-cookie with correct domain scope Performance: - Wrap ItemDoctor with React.memo to prevent unnecessary re-renders - Replace <img> with Next.js <Image> in blog Caption component Functionality: - Fix memory leak in Recode.js — store intervals in refs, cleanup on unmount - Add null guard on retryIcon.current before classList manipulation - Fix getParsedUserInfo in helper to handle malformed cookie gracefully Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
27 lines
719 B
JavaScript
27 lines
719 B
JavaScript
const DANGEROUS_TAGS = ['script', 'iframe', 'object', 'embed', 'link', 'meta', 'base', 'form'];
|
|
|
|
export function sanitizeHtml(html) {
|
|
if (!html || typeof html !== 'string') return '';
|
|
|
|
let sanitized = html;
|
|
|
|
DANGEROUS_TAGS.forEach((tag) => {
|
|
const openClose = new RegExp(`<${tag}[\\s\\S]*?(?:<\\/${tag}>|/?>)`, 'gi');
|
|
sanitized = sanitized.replace(openClose, '');
|
|
});
|
|
|
|
sanitized = sanitized.replace(/\s+on\w+\s*=\s*(?:"[^"]*"|'[^']*'|[^\s>]*)/gi, '');
|
|
sanitized = sanitized.replace(/(?:javascript|vbscript):/gi, '');
|
|
|
|
return sanitized;
|
|
}
|
|
|
|
export function safeJsonParse(str, fallback = null) {
|
|
if (!str) return fallback;
|
|
try {
|
|
return JSON.parse(str);
|
|
} catch {
|
|
return fallback;
|
|
}
|
|
}
|