- Added isomorphic-dompurify for improved XSS protection - Refactored token storage to use in-memory management for access tokens - Implemented server-side route handlers for OAuth token management - Introduced security headers in next.config.js - Removed client-side exposure of client_secret and sensitive tokens - Updated API interceptors to handle token refresh logic - Cleaned up cookie management for refresh tokens
25 lines
651 B
JavaScript
25 lines
651 B
JavaScript
import DOMPurify from "isomorphic-dompurify";
|
|
|
|
export function sanitizeHtml(html) {
|
|
if (!html || typeof html !== "string") return "";
|
|
|
|
return DOMPurify.sanitize(html, {
|
|
ALLOWED_TAGS: [
|
|
"p", "br", "strong", "em", "b", "i", "u", "ul", "ol", "li", "a",
|
|
"h2", "h3", "h4", "h5", "blockquote", "img", "span", "div",
|
|
"table", "thead", "tbody", "tr", "td", "th",
|
|
],
|
|
ALLOWED_ATTR: ["href", "target", "rel", "src", "alt", "title"],
|
|
ALLOW_DATA_ATTR: false,
|
|
});
|
|
}
|
|
|
|
export function safeJsonParse(str, fallback = null) {
|
|
if (!str) return fallback;
|
|
try {
|
|
return JSON.parse(str);
|
|
} catch {
|
|
return fallback;
|
|
}
|
|
}
|