mirror of
https://gitee.com/spark-store-project/spark-store
synced 2026-09-20 21:50:11 +08:00
fix: 安全加固 + 首页推荐优先加载解耦
- install-manager: queue-install JSON.parse 加 try-catch 防异常 payload - App.vue: openExternalUrl 协议白名单(http/https) 防恶意 scheme - AppDetailModal: sanitizeMoreContent 改用 textContent 防 v-html XSS - storeConfig: loadPriorityConfig 校验顶层结构,畸形数据回退 APM - App.vue onMounted: 首页推荐(loadHome+preloadHomeListApps) 与全量 应用加载(loadApps) 解耦,进入软件即优先显示首页推荐
This commit is contained in:
@@ -587,15 +587,16 @@ import type { App, AppReview, ReviewTags } from "../global/typedefinition";
|
||||
|
||||
/**
|
||||
* 净化后端返回的应用描述(v-html 前严格去除所有标签)。
|
||||
* 程序先将用户内容中的所有 HTML 标签剥离,再将 \n 转为 <br>。
|
||||
* <br> 是纯程序生成,不含任何用户输入,可安全放入 v-html。
|
||||
* 使用 textContent 做 HTML 实体转义,彻底杜绝 <script>/onerror/嵌套标签/编码绕过等 XSS;
|
||||
* 再将 \n 转为 <br>。<br> 是纯程序生成,不含任何用户输入,可安全放入 v-html。
|
||||
*/
|
||||
const sanitizeMoreContent = (raw: string): string => {
|
||||
if (!raw) return "";
|
||||
// 去除所有 HTML 标签,避免 XSS(包括 <script>/onerror/等)
|
||||
const stripped = raw.replace(/<[^>]*>/g, "");
|
||||
// 将 \n 转为安全的 <br>
|
||||
return stripped.replace(/\n/g, "<br>");
|
||||
// 用 textContent 转义所有 HTML 特殊字符(比正则替换 /<[^>]*>/g 更安全,防嵌套/编码绕过)
|
||||
const stripped = document.createElement("div");
|
||||
stripped.textContent = raw;
|
||||
// 将 \n 转为安全的 <br>(此时 textContent 已是转义后的纯文本字符串)
|
||||
return (stripped.textContent ?? "").replace(/\n/g, "<br>");
|
||||
};
|
||||
|
||||
const attrs = useAttrs();
|
||||
|
||||
Reference in New Issue
Block a user