Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed Link extension's commands not respecting XSS prevention via unallowed protocols #5945

Merged
merged 3 commits into from
Dec 19, 2024

Conversation

bdbch
Copy link
Member

@bdbch bdbch commented Dec 18, 2024

This pull request includes changes to improve error handling and validation for links in the Link extension. The most important changes include adding error handling in the React component, exporting the isAllowedUri function, and validating link protocols before setting or toggling links.

Implementation Approach

I added checks inside the setLink and toggleLink commands to see if the link being tried to set is actually valid. If not, we throw an error so the developer can implement error handling outside of the extension.

try {
  editor.chain().setLink('javascript:alert("Hello world")').focus().run()
} catch (e) {
  if (e.message === 'Invalid protocol') {
    alert('Please don\'t put XSS injections into our content please.')
  }
}

Testing Done

  1. Tested it locally on the Link demo (where I also added said check + error handler)
  2. Used the already existing test that will check if insertion of unwanted protocols works or not

Verification Steps

See above

Additional Notes

Because people can potentially also override said commands, I added an export for the isValidUri function to make it easy for people to add said checks themselves.

Checklist

  • I have created a changeset for this PR if necessary.
  • My changes do not break the library.
  • I have added tests where applicable.
  • I have followed the project guidelines.
  • I have fixed any lint issues.

Copy link

changeset-bot bot commented Dec 18, 2024

🦋 Changeset detected

Latest commit: 96e20bb

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 54 packages
Name Type
@tiptap/extension-link Patch
@tiptap/core Patch
@tiptap/extension-blockquote Patch
@tiptap/extension-bold Patch
@tiptap/extension-bubble-menu Patch
@tiptap/extension-bullet-list Patch
@tiptap/extension-character-count Patch
@tiptap/extension-code-block-lowlight Patch
@tiptap/extension-code-block Patch
@tiptap/extension-code Patch
@tiptap/extension-collaboration-cursor Patch
@tiptap/extension-collaboration Patch
@tiptap/extension-color Patch
@tiptap/extension-document Patch
@tiptap/extension-dropcursor Patch
@tiptap/extension-floating-menu Patch
@tiptap/extension-focus Patch
@tiptap/extension-font-family Patch
@tiptap/extension-gapcursor Patch
@tiptap/extension-hard-break Patch
@tiptap/extension-heading Patch
@tiptap/extension-highlight Patch
@tiptap/extension-history Patch
@tiptap/extension-horizontal-rule Patch
@tiptap/extension-image Patch
@tiptap/extension-italic Patch
@tiptap/extension-list-item Patch
@tiptap/extension-list-keymap Patch
@tiptap/extension-mention Patch
@tiptap/extension-ordered-list Patch
@tiptap/extension-paragraph Patch
@tiptap/extension-placeholder Patch
@tiptap/extension-strike Patch
@tiptap/extension-subscript Patch
@tiptap/extension-superscript Patch
@tiptap/extension-table-cell Patch
@tiptap/extension-table-header Patch
@tiptap/extension-table-row Patch
@tiptap/extension-table Patch
@tiptap/extension-task-item Patch
@tiptap/extension-task-list Patch
@tiptap/extension-text-align Patch
@tiptap/extension-text-style Patch
@tiptap/extension-text Patch
@tiptap/extension-typography Patch
@tiptap/extension-underline Patch
@tiptap/extension-youtube Patch
@tiptap/html Patch
@tiptap/pm Patch
@tiptap/react Patch
@tiptap/starter-kit Patch
@tiptap/suggestion Patch
@tiptap/vue-2 Patch
@tiptap/vue-3 Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

netlify bot commented Dec 18, 2024

Deploy Preview for tiptap-embed ready!

Name Link
🔨 Latest commit 96e20bb
🔍 Latest deploy log https://app.netlify.com/sites/tiptap-embed/deploys/6763ee9b3eb57500077da8ed
😎 Deploy Preview https://deploy-preview-5945--tiptap-embed.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Copy link

pkg-pr-new bot commented Dec 18, 2024

Open in Stackblitz

@tiptap/core

npm i https://pkg.pr.new/@tiptap/core@5945

@tiptap/extension-blockquote

npm i https://pkg.pr.new/@tiptap/extension-blockquote@5945

@tiptap/extension-bold

npm i https://pkg.pr.new/@tiptap/extension-bold@5945

@tiptap/extension-bullet-list

npm i https://pkg.pr.new/@tiptap/extension-bullet-list@5945

@tiptap/extension-bubble-menu

npm i https://pkg.pr.new/@tiptap/extension-bubble-menu@5945

@tiptap/extension-character-count

npm i https://pkg.pr.new/@tiptap/extension-character-count@5945

@tiptap/extension-code

npm i https://pkg.pr.new/@tiptap/extension-code@5945

@tiptap/extension-code-block

npm i https://pkg.pr.new/@tiptap/extension-code-block@5945

@tiptap/extension-code-block-lowlight

npm i https://pkg.pr.new/@tiptap/extension-code-block-lowlight@5945

@tiptap/extension-collaboration

npm i https://pkg.pr.new/@tiptap/extension-collaboration@5945

@tiptap/extension-collaboration-cursor

npm i https://pkg.pr.new/@tiptap/extension-collaboration-cursor@5945

@tiptap/extension-color

npm i https://pkg.pr.new/@tiptap/extension-color@5945

@tiptap/extension-document

npm i https://pkg.pr.new/@tiptap/extension-document@5945

@tiptap/extension-dropcursor

npm i https://pkg.pr.new/@tiptap/extension-dropcursor@5945

@tiptap/extension-floating-menu

npm i https://pkg.pr.new/@tiptap/extension-floating-menu@5945

@tiptap/extension-focus

npm i https://pkg.pr.new/@tiptap/extension-focus@5945

@tiptap/extension-font-family

npm i https://pkg.pr.new/@tiptap/extension-font-family@5945

@tiptap/extension-gapcursor

npm i https://pkg.pr.new/@tiptap/extension-gapcursor@5945

@tiptap/extension-hard-break

npm i https://pkg.pr.new/@tiptap/extension-hard-break@5945

@tiptap/extension-heading

npm i https://pkg.pr.new/@tiptap/extension-heading@5945

@tiptap/extension-highlight

npm i https://pkg.pr.new/@tiptap/extension-highlight@5945

@tiptap/extension-history

npm i https://pkg.pr.new/@tiptap/extension-history@5945

@tiptap/extension-horizontal-rule

npm i https://pkg.pr.new/@tiptap/extension-horizontal-rule@5945

@tiptap/extension-image

npm i https://pkg.pr.new/@tiptap/extension-image@5945

@tiptap/extension-italic

npm i https://pkg.pr.new/@tiptap/extension-italic@5945

@tiptap/extension-link

npm i https://pkg.pr.new/@tiptap/extension-link@5945

@tiptap/extension-list-item

npm i https://pkg.pr.new/@tiptap/extension-list-item@5945

@tiptap/extension-list-keymap

npm i https://pkg.pr.new/@tiptap/extension-list-keymap@5945

@tiptap/extension-mention

npm i https://pkg.pr.new/@tiptap/extension-mention@5945

@tiptap/extension-ordered-list

npm i https://pkg.pr.new/@tiptap/extension-ordered-list@5945

@tiptap/extension-paragraph

npm i https://pkg.pr.new/@tiptap/extension-paragraph@5945

@tiptap/extension-placeholder

npm i https://pkg.pr.new/@tiptap/extension-placeholder@5945

@tiptap/extension-strike

npm i https://pkg.pr.new/@tiptap/extension-strike@5945

@tiptap/extension-subscript

npm i https://pkg.pr.new/@tiptap/extension-subscript@5945

@tiptap/extension-superscript

npm i https://pkg.pr.new/@tiptap/extension-superscript@5945

@tiptap/extension-table

npm i https://pkg.pr.new/@tiptap/extension-table@5945

@tiptap/extension-table-cell

npm i https://pkg.pr.new/@tiptap/extension-table-cell@5945

@tiptap/extension-table-header

npm i https://pkg.pr.new/@tiptap/extension-table-header@5945

@tiptap/extension-table-row

npm i https://pkg.pr.new/@tiptap/extension-table-row@5945

@tiptap/extension-task-item

npm i https://pkg.pr.new/@tiptap/extension-task-item@5945

@tiptap/extension-task-list

npm i https://pkg.pr.new/@tiptap/extension-task-list@5945

@tiptap/extension-text-align

npm i https://pkg.pr.new/@tiptap/extension-text-align@5945

@tiptap/extension-text

npm i https://pkg.pr.new/@tiptap/extension-text@5945

@tiptap/extension-text-style

npm i https://pkg.pr.new/@tiptap/extension-text-style@5945

@tiptap/extension-typography

npm i https://pkg.pr.new/@tiptap/extension-typography@5945

@tiptap/extension-underline

npm i https://pkg.pr.new/@tiptap/extension-underline@5945

@tiptap/extension-youtube

npm i https://pkg.pr.new/@tiptap/extension-youtube@5945

@tiptap/html

npm i https://pkg.pr.new/@tiptap/html@5945

@tiptap/react

npm i https://pkg.pr.new/@tiptap/react@5945

@tiptap/pm

npm i https://pkg.pr.new/@tiptap/pm@5945

@tiptap/starter-kit

npm i https://pkg.pr.new/@tiptap/starter-kit@5945

@tiptap/suggestion

npm i https://pkg.pr.new/@tiptap/suggestion@5945

@tiptap/vue-2

npm i https://pkg.pr.new/@tiptap/vue-2@5945

@tiptap/vue-3

npm i https://pkg.pr.new/@tiptap/vue-3@5945

commit: 96e20bb

@bdbch
Copy link
Member Author

bdbch commented Dec 19, 2024

@nperez0111 done

Copy link
Contributor

@nperez0111 nperez0111 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. I think to release we got to make something not a major. I would look into it but I have an appointment right now

@bdbch bdbch merged commit 1c2fefe into main Dec 19, 2024
15 checks passed
@bdbch bdbch deleted the fix/link-xss-fix branch December 19, 2024 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants