dengliming opened a new issue, #614: URL: https://github.com/apache/shenyu-dashboard/issues/614
## Description When the debug response is not JSON, `ApiDebug` renders `ReactHtmlParser(responseInfo.body)` directly into the dashboard DOM. The body comes from whatever upstream the gateway proxies to (or any address the user is pointed at via the environment selector), so `<iframe>`, `<form>`, `<style>`, `<a href="javascript:...">` etc. in the response are rendered inside the authenticated admin origin. ## Location (Lines refer to `master @ 83969a5`.) - `src/routes/Document/components/ApiDebug.js:40,493` ## Impact A malicious or compromised upstream can inject markup into the admin page (phishing forms, clickjacking, style injection). Script tags are stripped by react-html-parser, but the remaining vectors are still significant for an admin UI whose token is in `sessionStorage`. ## Suggested fix Render non-JSON bodies as plain text inside a `<pre>` (or in a read-only textarea) and drop the `react-html-parser` dependency from this component. ## Related existing None -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
