This is an automated email from the ASF dual-hosted git repository.

hainenber pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/superset.git


The following commit(s) were added to refs/heads/master by this push:
     new ba453d3cb43 fix(sec): sanitize HTML text before shown as impact item's 
label (#43825)
ba453d3cb43 is described below

commit ba453d3cb43f6b2b4b20ead3de2cce1543fab28f
Author: Đỗ Trọng Hải <[email protected]>
AuthorDate: Sat Oct 3 11:44:16 2026 +0700

    fix(sec): sanitize HTML text before shown as impact item's label (#43825)
---
 .../pages/ArchivedList/ArchivedDatasetPurgeModal.tsx   |  3 ++-
 superset-frontend/src/utils/urlUtils.ts                | 17 +++++++++++++++++
 .../TimeTable/components/LeftCell/LeftCell.tsx         | 18 +-----------------
 3 files changed, 20 insertions(+), 18 deletions(-)

diff --git 
a/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx 
b/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
index 4d93b8c19ad..fc49b356e34 100644
--- a/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
+++ b/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
@@ -25,6 +25,7 @@ import type {
   PurgeImpactCollection,
   PurgeImpactItem,
 } from './types';
+import { toSafeHref } from 'src/utils/urlUtils';
 
 const ImpactSection = styled.section`
   ${({ theme }) => `
@@ -62,7 +63,7 @@ function ImpactItem({ item }: { item: PurgeImpactItem }) {
   );
   const label =
     item.url && isSafeAppPath && !item.archived ? (
-      <a href={item.url}>{item.name}</a>
+      <a href={toSafeHref(item.url)}>{item.name}</a>
     ) : (
       item.name
     );
diff --git a/superset-frontend/src/utils/urlUtils.ts 
b/superset-frontend/src/utils/urlUtils.ts
index f38611ebafd..b4f48c29313 100644
--- a/superset-frontend/src/utils/urlUtils.ts
+++ b/superset-frontend/src/utils/urlUtils.ts
@@ -348,3 +348,20 @@ export function toQueryString(params: Record<string, 
any>): string {
   });
   return queryParts.length > 0 ? `?${queryParts.join('&')}` : '';
 }
+
+/**
+ * Confines a caller-supplied URL to http(s) and relative schemes before
+ * it's rendered as a link. Returns undefined for anything else, degrading
+ * the cell to plain text.
+ */
+export const toSafeHref = (url: string): string | undefined => {
+  try {
+    const { protocol } = new URL(url, window.location.origin);
+    if (protocol === 'http:' || protocol === 'https:') {
+      return url;
+    }
+  } catch {
+    // fall through: unparseable URLs are not rendered as links
+  }
+  return undefined;
+};
diff --git 
a/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
 
b/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
index b628e31d7e8..dbb8a242dc4 100644
--- 
a/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
+++ 
b/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
@@ -21,6 +21,7 @@ import Mustache from 'mustache';
 import { Typography } from '@superset-ui/core/components';
 import { MetricOption } from '@superset-ui/chart-controls';
 import type { Row, ColumnRow, MetricRow } from '../../types';
+import { toSafeHref } from 'src/utils/urlUtils';
 
 interface LeftCellProps {
   row: Row;
@@ -28,23 +29,6 @@ interface LeftCellProps {
   url?: string;
 }
 
-/**
- * Confines a caller-supplied URL to http(s) and relative schemes before
- * it's rendered as a link. Returns undefined for anything else, degrading
- * the cell to plain text.
- */
-export const toSafeHref = (url: string): string | undefined => {
-  try {
-    const { protocol } = new URL(url, window.location.origin);
-    if (protocol === 'http:' || protocol === 'https:') {
-      return url;
-    }
-  } catch {
-    // fall through: unparseable URLs are not rendered as links
-  }
-  return undefined;
-};
-
 /**
  * Renders the left cell containing either column labels or metric information
  */

Reply via email to