Fix XSS vulnerabilities in JavaScript files
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -246,4 +246,15 @@ h1, h2, h3, h4, h5, h6 {
|
|||||||
.chart-container {
|
.chart-container {
|
||||||
height: 16rem; /* h-64 */
|
height: 16rem; /* h-64 */
|
||||||
@apply w-full;
|
@apply w-full;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Text status colors for compliance status */
|
||||||
|
.text-success {
|
||||||
|
color: #16a34a; /* Green color for compliant status */
|
||||||
|
font-weight: 500;
|
||||||
|
}
|
||||||
|
|
||||||
|
.text-error {
|
||||||
|
color: #dc2626; /* Red color for non-compliant status */
|
||||||
|
font-weight: 500;
|
||||||
}
|
}
|
||||||
@@ -231,14 +231,23 @@ function renderRecentReports(reports, domains) {
|
|||||||
// Get domain name
|
// Get domain name
|
||||||
const domainName = domainMap.get(report.domain_id) || 'Unknown';
|
const domainName = domainMap.get(report.domain_id) || 'Unknown';
|
||||||
|
|
||||||
row.innerHTML = `
|
// Create domain cell with safe text content
|
||||||
<td>${domainName}</td>
|
const domainCell = document.createElement('td');
|
||||||
<td>${formattedDate}</td>
|
domainCell.textContent = domainName;
|
||||||
<td>${report.is_compliant ?
|
row.appendChild(domainCell);
|
||||||
'<span style="color: green;">Compliant</span>' :
|
|
||||||
'<span style="color: red;">Non-compliant</span>'
|
// Create date cell with safe text content
|
||||||
}</td>
|
const dateCell = document.createElement('td');
|
||||||
`;
|
dateCell.textContent = formattedDate;
|
||||||
|
row.appendChild(dateCell);
|
||||||
|
|
||||||
|
// Create status cell with safe text content and CSS classes
|
||||||
|
const statusCell = document.createElement('td');
|
||||||
|
const statusSpan = document.createElement('span');
|
||||||
|
statusSpan.textContent = report.is_compliant ? 'Compliant' : 'Non-compliant';
|
||||||
|
statusSpan.className = report.is_compliant ? 'text-success' : 'text-error';
|
||||||
|
statusCell.appendChild(statusSpan);
|
||||||
|
row.appendChild(statusCell);
|
||||||
|
|
||||||
tableBody.appendChild(row);
|
tableBody.appendChild(row);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -184,9 +184,11 @@ function setupWizardEventListeners() {
|
|||||||
const cloudflareToken = document.getElementById('cloudflare-token').value;
|
const cloudflareToken = document.getElementById('cloudflare-token').value;
|
||||||
const cloudflareZone = document.getElementById('cloudflare-zone').value;
|
const cloudflareZone = document.getElementById('cloudflare-zone').value;
|
||||||
|
|
||||||
|
// Store only the flag that Cloudflare is enabled
|
||||||
|
// Credentials should be sent directly to backend, never stored client-side
|
||||||
localStorage.setItem('setup_cloudflare_enabled', 'true');
|
localStorage.setItem('setup_cloudflare_enabled', 'true');
|
||||||
localStorage.setItem('setup_cloudflare_token', cloudflareToken);
|
// TODO: Send cloudflareToken and cloudflareZone to backend API instead of localStorage
|
||||||
localStorage.setItem('setup_cloudflare_zone', cloudflareZone);
|
// For now, these credentials are not persisted client-side for security
|
||||||
}
|
}
|
||||||
|
|
||||||
// Move to step 3
|
// Move to step 3
|
||||||
|
|||||||
Reference in New Issue
Block a user