Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@
"eslint-plugin-simple-import-sort": "^12.1.1",
"fast-geoip": "^1.1.88",
"html2canvas": "^1.4.1",
"isomorphic-dompurify": "^3.12.0",
"lodash.debounce": "4.0.8",
"lodash.unescape": "4.0.1",
"mixpanel-browser": "^2.65.0",
Expand Down
6 changes: 5 additions & 1 deletion src/components/OurProjectsModal/OurProjectsModal.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ import { Tooltip as ReactTooltip } from 'react-tooltip';

import { TRouter } from '@local-types/global';

import { sanitizeHtml } from '@lib/sanitizeHtml';

import ourProjectsData from '@data/ourProjects';

import Button from '@components/Button';
Expand Down Expand Up @@ -93,7 +95,9 @@ const OurProjectsModal: FC<OurProjectsModalProps> = ({
</div>

<div
dangerouslySetInnerHTML={{ __html: project.description }}
dangerouslySetInnerHTML={{
__html: sanitizeHtml(project.description),
}}
className={styles.description}
/>

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
import { useRouter } from 'next/router';

import { sanitizeHtml } from '@lib/sanitizeHtml';

import rawContent from './InformationBias.content';

import styles from './InformationBias.module.scss';
Expand Down Expand Up @@ -45,8 +47,8 @@ export function After() {
<div className={styles.specTable}>
{c.after.specs.map(([k, v]) => (
<div key={k} className={styles.specRow}>
<span dangerouslySetInnerHTML={{ __html: k }} />
<strong dangerouslySetInnerHTML={{ __html: v }} />
<span dangerouslySetInnerHTML={{ __html: sanitizeHtml(k) }} />
<strong dangerouslySetInnerHTML={{ __html: sanitizeHtml(v) }} />
</div>
))}
</div>
Expand Down
4 changes: 3 additions & 1 deletion src/components/_uxcp/CountryBiasMap/BiasPanel/BiasPanel.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ import {
import type { StrapiBiasType } from '@local-types/data';
import type { TRouter } from '@local-types/global';

import { sanitizeHtml } from '@lib/sanitizeHtml';

import { countryBiasByLocale, REGION_COLORS } from '@data/countryBias';

import FlagImage from '../FlagImage';
Expand Down Expand Up @@ -204,7 +206,7 @@ const BiasPanel = forwardRef<HTMLDivElement, BiasPanelProps>(
<div
className={styles.BiasShort}
dangerouslySetInnerHTML={{
__html: bias.description ?? '',
__html: sanitizeHtml(bias.description),
}}
/>
</Link>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ import { Tooltip as ReactTooltip } from 'react-tooltip';

import { TRouter } from '@local-types/global';

import { sanitizeHtml } from '@lib/sanitizeHtml';

import decisionTable from '@data/decisionTable';

import Button from '@components/Button';
Expand Down Expand Up @@ -105,7 +107,9 @@ const DecisionTableModal = (props: DecisionTableModalProps) => {
place={'top'}
>
<span
dangerouslySetInnerHTML={{ __html: props.descriptionOfBias }}
dangerouslySetInnerHTML={{
__html: sanitizeHtml(props.descriptionOfBias),
}}
/>
</ReactTooltip>
</div>
Expand Down
9 changes: 9 additions & 0 deletions src/lib/sanitizeHtml.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
import DOMPurify from 'isomorphic-dompurify';

export const sanitizeHtml = (dirty: unknown): string => {
if (dirty == null || dirty === '') return '';
return DOMPurify.sanitize(String(dirty), {
USE_PROFILES: { html: true },
ADD_ATTR: ['target', 'rel'],
});
};
Loading
Loading