Skip to content

Release 1.3.4 - security fixes. - #39

Merged
BrainInBlack merged 3 commits into
mainfrom
develop
Sep 30, 2026
Merged

BrainInBlack merged 3 commits into
mainfrom
develop

Conversation

@BrainInBlack

Copy link
Copy Markdown
Owner

Release 1.3.4 - security fixes. Maps render exactly as before.

  • SVG sanitizer: fail-closed url() check. A quoted url() whose target held
    ', " or ) matched nothing in the old token regex, so off-document URLs
    survived in style/paint attributes (e.g. a root background that
    beacons the viewer's IP on every render). Every url( opener must now be a
    strict #fragment ref; regression tests added for the quote/paren variants.
  • Content Security Policy: default-src 'none', img-src 'self' data: blob:,
    connect-src 'self'. The single-file build gets its inline script's sha256
    appended to script-src at build time (no 'unsafe-inline' scripts).
  • CHANGELOG 1.3.4 section, version 1.3.3 -> 1.3.4
    (includes lucide-static 1.46.0 -> 1.47.0 from deps: bump lucide-static from 1.46.0 to 1.47.0 #37, no shipped icon changed)

Verified locally on Node 26.10.0: typecheck clean, 226 tests pass, npm audit 0,
build produces dist/download/netgraph.html. CSP checked in the dev server, the
web build (preview) and the offline copy over http and from disk - the planted
beacon is blocked, the example map renders, and Download Offline Copy works.

🤖 Generated with Claude Code

BrainInBlack and others added 3 commits September 30, 2026 22:16
A quoted url() whose target contained ', " or ) matched nothing in the
old token regex, so the check returned true and off-document URLs
survived in style/paint attributes (e.g. a root <svg> background that
beacons the viewer's IP on every render). Count every url( opener and
require each to be a strict #fragment ref; any mismatch drops the
attribute. Adds regression tests for the quote/paren variants.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Defense-in-depth behind the SVG sanitizer and escapeHtml: the page may
not load or send anything cross-origin (default-src 'none', img-src
'self' data: blob:, connect-src 'self'). style-src keeps 'unsafe-inline'
for the innerHTML style="" attributes.

The single-file build inlines its JS, so a post-generateBundle plugin
appends the inline script's sha256 to script-src instead of allowing
'unsafe-inline' scripts; it fails the build if the CSP meta is missing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Security release: fail-closed url() check in the SVG sanitizer and a
Content Security Policy for the page and the offline copy. Also picks
up lucide-static ^1.47.0 (no shipped icon changed). Bump the version
and add the 1.3.4 CHANGELOG section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@BrainInBlack
BrainInBlack merged commit e4cf338 into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant