Skip to content

Disallow specific data attributes from DOMPurify's default config [RUN AS-IF-FOSS] [RUN ALL RSPEC]

Dheeraj Joshi requested to merge djadmin-dompurify-data-attrs into master

What does this MR do?

This MR sanitizes some of the data-* attributes used by @rails/ujs. See gitlab-ui#1421 (comment 617098438) for context.

This is to add defense-in-depth for preventing security issues like XSS.

Screenshots (strongly suggested)

No visual changes

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

Does this MR contain changes to processing or storing of credentials or tokens, authorization and authentication methods or other items described in the security review guidelines? If not, then delete this Security section.

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Dheeraj Joshi

Merge request reports