fix: address security findings from final review
- Replace regex HTML sanitization with DOMPurify in NoteWidget (XSS fix) - Remove allow-same-origin from default iframe sandbox in EmbedWidget - Add URL scheme validation for embed URLs (http/https only) - Install isomorphic-dompurify dependency
This commit is contained in:
Generated
+734
-3
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user