fix(core): prevent infinite loops in clobbered elements check#54425
Closed
AndrewKushnir wants to merge 1 commit intoangular:mainfrom
Closed
fix(core): prevent infinite loops in clobbered elements check#54425AndrewKushnir wants to merge 1 commit intoangular:mainfrom
AndrewKushnir wants to merge 1 commit intoangular:mainfrom
Conversation
01fd9df to
894b81e
Compare
alfaproject
reviewed
Feb 15, 2024
This commit updates HTML sanitization logic to avoid infinite loops in case clobbered elements contain fields like `nextSibling` or `parentNode`. Those fields are used for DOM traversal and this update makes sure that those calls return valid results. Also this commit fixes an issue when clobbering `nodeName` causes JS exceptions.
894b81e to
e92a3f7
Compare
Contributor
Author
pkozlowski-opensource
approved these changes
Mar 4, 2024
Member
pkozlowski-opensource
left a comment
There was a problem hiding this comment.
LGTM
Reviewed-for: fw-core
Reviewed-for: fw-security
Contributor
Author
|
Caretaker notes
|
Contributor
|
This PR was merged into the repository by commit eaff724. |
atscott
pushed a commit
that referenced
this pull request
Mar 11, 2024
This commit updates HTML sanitization logic to avoid infinite loops in case clobbered elements contain fields like `nextSibling` or `parentNode`. Those fields are used for DOM traversal and this update makes sure that those calls return valid results. Also this commit fixes an issue when clobbering `nodeName` causes JS exceptions. PR Close #54425
atscott
pushed a commit
that referenced
this pull request
Mar 11, 2024
This commit updates HTML sanitization logic to avoid infinite loops in case clobbered elements contain fields like `nextSibling` or `parentNode`. Those fields are used for DOM traversal and this update makes sure that those calls return valid results. Also this commit fixes an issue when clobbering `nodeName` causes JS exceptions. PR Close #54425
|
This issue has been automatically locked due to inactivity. Read more about our automatic conversation locking policy. This action has been performed automatically by a bot. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This commit updates HTML sanitization logic to avoid infinite loops in case clobbered elements contain fields like
nextSiblingorparentNode. Those fields are used for DOM traversal and this update makes sure that those calls return valid results.Also this commit fixes an issue when clobbering
nodeNamecauses JS exceptions.(more context in the internal ticket: b/323800512)
PR Type
What kind of change does this PR introduce?
Does this PR introduce a breaking change?