refac: apply DOMPurify to excel and office HTML render assignments (#24468)

This commit is contained in:
Classic298 2026-05-08 22:10:31 +02:00 • committed by GitHub
parent 7eeff2fdf9
commit 3746339cfc
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 5 additions and 3 deletions

View file

@ -455,7 +455,8 @@
selectedExcelSheet = excelSheetNames[0];
const { excelToTable } = await import('$lib/utils/excelToTable');
const result = await excelToTable(wb.Sheets[selectedExcelSheet]);
fileOfficeHtml = result.html;
const DOMPurify = (await import('dompurify')).default;
fileOfficeHtml = DOMPurify.sanitize(result.html);
}
} else if (ext === 'pptx') {
const { pptxToImages } = await import('$lib/utils/pptxToHtml');
@ -1282,7 +1283,8 @@
selectedExcelSheet = sheet;
const { excelToTable } = await import('$lib/utils/excelToTable');
const result = await excelToTable(excelWorkbook.Sheets[sheet]);
fileOfficeHtml = result.html;
const DOMPurify = (await import('dompurify')).default;
fileOfficeHtml = DOMPurify.sanitize(result.html);
}}
baseUrl={selectedTerminal?.url ?? ''}
apiKey={selectedTerminal?.key ?? ''}

View file

@ -161,7 +161,7 @@
const { excelToTable } = await import('$lib/utils/excelToTable');
const worksheet = excelWorkbook.Sheets[selectedSheet];
const result = await excelToTable(worksheet);
excelHtml = result.html;
excelHtml = DOMPurify.sanitize(result.html);
rowCount = result.rowCount;
};