fix(awe-client-react): sanitize the HTML of grid cells

Problem to solve

The React grid renders the text of every cell as HTML (html-react-parser in utilities/structure.js, cell renderer for text values) without sanitizing it. A value coming from the database or from user input that contains markup or a script-carrying attribute could be interpreted by the browser (stored XSS). This was found reading the code and must be confirmed in a browser.

Goals

  • No unsanitized HTML from data reaches the DOM in any grid cell of the React engine.
  • Columns that are meant to render HTML (formatted-text, #800) sanitize it.

What does success look like, and how can we measure that?

  • A browser test on the React test application: a cell value with a script-carrying attribute is shown as text (or sanitized) and nothing executes
  • Plain text cells render text, not HTML
  • Unit tests for the cell renderer cover markup, event-handler attributes and javascript: URLs
  • Same check done on the AngularJS engine and documented

Related: #800.