npub10l…sv2ux on Nostr: [ steve02081504/fount ] security: clean up code-scanning alerts (#337) * security: ...
[ steve02081504/fount ] security: clean up code-scanning alerts (#337)
* security: address code-scanning alerts
- Replace Math.random with crypto in service generators / session / svg inliner / userscript
- Escape toast text and notification i18n attrs; keep sanctioned HTML toast channel
- Validate redirect/hostnames (login, tutorial, deskpet, char-download, badges)
- Clamp backend-driven toast duration; secure cookie on https
- Restrict workflow token permissions; harden regexp escapes
- Add toast frontend regression tests (plain text escaped, custom HTML kept)
https://github.com/steve02081504/fount/commit/045f7ed822b2753e8882296a14028c5d6f363e32Published at
2026-09-15 17:00:24 UTCEvent JSON
{
"id": "226c7ef036782094fa46f62acac718c5b15316d8006fe21634a0c82ed47d0fa0",
"pubkey": "7febe2a59aa826f8f6337b4101939eaac82fd4e6ca5f3c7b8f13ca03ad26f2bf",
"created_at": 1789491624,
"kind": 1,
"tags": [
[
"proxy",
"https://github.com/steve02081504/fount/commit/045f7ed822b2753e8882296a14028c5d6f363e32",
"web"
]
],
"content": "[ steve02081504/fount ] security: clean up code-scanning alerts (#337)\n\n* security: address code-scanning alerts\n\n- Replace Math.random with crypto in service generators / session / svg inliner / userscript\n- Escape toast text and notification i18n attrs; keep sanctioned HTML toast channel\n- Validate redirect/hostnames (login, tutorial, deskpet, char-download, badges)\n- Clamp backend-driven toast duration; secure cookie on https\n- Restrict workflow token permissions; harden regexp escapes\n- Add toast frontend regression tests (plain text escaped, custom HTML kept)\nhttps://github.com/steve02081504/fount/commit/045f7ed822b2753e8882296a14028c5d6f363e32",
"sig": "4a9ed63c15d9d120f60cad46e90dd8e3bd244cfa8597b708b367f6a4d423cd01ab507b1537d2195d9568018843fbc1aa64208bc5da91e9a4d9963b66c0fcd1fa"
}