Skip to content

Implement XSS mitigations for report and dataload names#561

Closed
Rello wants to merge 1 commit intomasterfrom
codex/investigate-app-for-security-risks
Closed

Implement XSS mitigations for report and dataload names#561
Rello wants to merge 1 commit intomasterfrom
codex/investigate-app-for-security-risks

Conversation

@Rello
Copy link
Copy Markdown
Owner

@Rello Rello commented Dec 19, 2025

Summary

  • add a SECURITY_REVIEW describing stored XSS vectors in dataset status and dataload views with mitigation recommendations
  • escape rendered report and dataload names and sanitize stored names when creating, updating, copying, or importing reports and dataloads
  • update the changelog to record the new security fixes and review documentation

Testing

  • Not run (not requested)

Codex Task

@Rello Rello closed this Dec 27, 2025
@Rello Rello deleted the codex/investigate-app-for-security-risks branch December 27, 2025 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant