fix(awe-client-react): sanitize the HTML of grid cells
Problem to solve
The React grid renders the text of every cell as HTML (html-react-parser in utilities/structure.js, cell renderer for text values) without sanitizing it. A value coming from the database or from user input that contains markup or a script-carrying attribute could be interpreted by the browser (stored XSS). This was found reading the code and must be confirmed in a browser.
Goals
- No unsanitized HTML from data reaches the DOM in any grid cell of the React engine.
- Columns that are meant to render HTML (
formatted-text, #800) sanitize it.
What does success look like, and how can we measure that?
- A browser test on the React test application: a cell value with a script-carrying attribute is shown as text (or sanitized) and nothing executes
- Plain text cells render text, not HTML
- Unit tests for the cell renderer cover markup, event-handler attributes and
javascript:URLs - Same check done on the AngularJS engine and documented
Related: #800.