Files
davila7__claude-code-templates/docs/js/search-functionality.js
daniel 0f4aaa7217 security: Fix XSS vulnerabilities in docs site and dashboard
Static site (docs/js/):
- Add escapeHTML() utility to utils.js for sanitizing dynamic content
- Apply escapeHTML to component names, descriptions, categories, and
  install commands in card generation (search-functionality.js,
  index-events.js)
- Replace innerHTML with DOM methods for search category tags

Dashboard:
- Create shared TypeIcon component using DOMParser for safe SVG
  rendering (rejects malformed SVG via parsererror check)
- Remove all dangerouslySetInnerHTML usage from SearchModal,
  ComponentGrid, TrendingView, and MyComponentsView
- Clean up unused ICONS imports

Resolves CLA-23

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-20 23:13:17 -05:00

40 KiB