From fa6edfbcde2473ce7d35262a45a56fae84c60e6e Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 15 Mar 2026 15:31:49 +0100 Subject: [PATCH] Fix stored XSS vulnerabilities and unauthenticated auth toggle - Sanitize project notes with DOMPurify before rendering via dangerouslySetInnerHTML (ProjectDetailPage.tsx) - Replace hand-rolled HTML sanitizer with DOMPurify in ProjectPageModal to prevent attribute injection via crafted 3MF href values - Block /api/v1/auth/setup when auth is already enabled to prevent unauthenticated clients from disabling authentication remotely --- CHANGELOG.md | 3 + backend/app/api/routes/auth.py | 8 +- frontend/package-lock.json | 15 + frontend/package.json | 1 + frontend/src/components/ProjectPageModal.tsx | 53 +- frontend/src/pages/ProjectDetailPage.tsx | 3 +- .../{index-jwN56PpH.js => index-CyeSJFXC.js} | 885 +++++++++--------- static/index.html | 2 +- 8 files changed, 479 insertions(+), 491 deletions(-) rename static/assets/{index-jwN56PpH.js => index-CyeSJFXC.js} (71%) diff --git a/CHANGELOG.md b/CHANGELOG.md index f58b336ec..c0429475a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -35,6 +35,9 @@ All notable changes to Bambuddy will be documented in this file. - **Spool Assignment Applies Wrong Filament Profile** ([#681](https://github.com/maziggy/bambuddy/issues/681)) — Assigning a spool with a specific filament variant (e.g. "Generic PLA Silk") to an AMS slot applied the base profile instead (e.g. "Generic PLA"). The Bambu Cloud API returns only the base `filament_id` for versioned setting IDs (`GFSL99` → `GFL99`), ignoring variant suffixes (`GFSL99_01`). Added a cross-check that compares the resolved filament name against the spool's stored preset name and corrects the filament ID via reverse lookup when they don't match (e.g. `GFL99` → `GFL96` for "Generic PLA Silk"). Reported by @peter-k-de. ### Security +- **Stored XSS via Project Notes** — Project notes were rendered with `dangerouslySetInnerHTML` without sanitization, allowing injected ` +