Fix stored XSS vulnerabilities and unauthenticated auth toggle

- Sanitize project notes with DOMPurify before rendering via
    dangerouslySetInnerHTML (ProjectDetailPage.tsx)
  - Replace hand-rolled HTML sanitizer with DOMPurify in ProjectPageModal
    to prevent attribute injection via crafted 3MF href values
  - Block /api/v1/auth/setup when auth is already enabled to prevent
    unauthenticated clients from disabling authentication remotely
This commit is contained in:
maziggy
2026-03-15 15:31:49 +01:00
parent 0feed83ce4
commit fa6edfbcde
8 changed files with 479 additions and 491 deletions
+1
View File
@@ -28,6 +28,7 @@
"@tiptap/react": "^3.11.1",
"@tiptap/starter-kit": "^3.11.1",
"@types/three": "^0.181.0",
"dompurify": "^3.3.3",
"gcode-preview": "^2.18.0",
"i18next": "25.6.3",
"i18next-browser-languagedetector": "^8.2.0",