This is an automated email from the ASF dual-hosted git repository.
hainenber pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/superset.git
The following commit(s) were added to refs/heads/master by this push:
new ba453d3cb43 fix(sec): sanitize HTML text before shown as impact item's
label (#43825)
ba453d3cb43 is described below
commit ba453d3cb43f6b2b4b20ead3de2cce1543fab28f
Author: Đỗ Trọng Hải <[email protected]>
AuthorDate: Sat Oct 3 11:44:16 2026 +0700
fix(sec): sanitize HTML text before shown as impact item's label (#43825)
---
.../pages/ArchivedList/ArchivedDatasetPurgeModal.tsx | 3 ++-
superset-frontend/src/utils/urlUtils.ts | 17 +++++++++++++++++
.../TimeTable/components/LeftCell/LeftCell.tsx | 18 +-----------------
3 files changed, 20 insertions(+), 18 deletions(-)
diff --git
a/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
b/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
index 4d93b8c19ad..fc49b356e34 100644
--- a/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
+++ b/superset-frontend/src/pages/ArchivedList/ArchivedDatasetPurgeModal.tsx
@@ -25,6 +25,7 @@ import type {
PurgeImpactCollection,
PurgeImpactItem,
} from './types';
+import { toSafeHref } from 'src/utils/urlUtils';
const ImpactSection = styled.section`
${({ theme }) => `
@@ -62,7 +63,7 @@ function ImpactItem({ item }: { item: PurgeImpactItem }) {
);
const label =
item.url && isSafeAppPath && !item.archived ? (
- <a href={item.url}>{item.name}</a>
+ <a href={toSafeHref(item.url)}>{item.name}</a>
) : (
item.name
);
diff --git a/superset-frontend/src/utils/urlUtils.ts
b/superset-frontend/src/utils/urlUtils.ts
index f38611ebafd..b4f48c29313 100644
--- a/superset-frontend/src/utils/urlUtils.ts
+++ b/superset-frontend/src/utils/urlUtils.ts
@@ -348,3 +348,20 @@ export function toQueryString(params: Record<string,
any>): string {
});
return queryParts.length > 0 ? `?${queryParts.join('&')}` : '';
}
+
+/**
+ * Confines a caller-supplied URL to http(s) and relative schemes before
+ * it's rendered as a link. Returns undefined for anything else, degrading
+ * the cell to plain text.
+ */
+export const toSafeHref = (url: string): string | undefined => {
+ try {
+ const { protocol } = new URL(url, window.location.origin);
+ if (protocol === 'http:' || protocol === 'https:') {
+ return url;
+ }
+ } catch {
+ // fall through: unparseable URLs are not rendered as links
+ }
+ return undefined;
+};
diff --git
a/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
b/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
index b628e31d7e8..dbb8a242dc4 100644
---
a/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
+++
b/superset-frontend/src/visualizations/TimeTable/components/LeftCell/LeftCell.tsx
@@ -21,6 +21,7 @@ import Mustache from 'mustache';
import { Typography } from '@superset-ui/core/components';
import { MetricOption } from '@superset-ui/chart-controls';
import type { Row, ColumnRow, MetricRow } from '../../types';
+import { toSafeHref } from 'src/utils/urlUtils';
interface LeftCellProps {
row: Row;
@@ -28,23 +29,6 @@ interface LeftCellProps {
url?: string;
}
-/**
- * Confines a caller-supplied URL to http(s) and relative schemes before
- * it's rendered as a link. Returns undefined for anything else, degrading
- * the cell to plain text.
- */
-export const toSafeHref = (url: string): string | undefined => {
- try {
- const { protocol } = new URL(url, window.location.origin);
- if (protocol === 'http:' || protocol === 'https:') {
- return url;
- }
- } catch {
- // fall through: unparseable URLs are not rendered as links
- }
- return undefined;
-};
-
/**
* Renders the left cell containing either column labels or metric information
*/