Skip to content

fix(security): resolve open CodeQL alerts (XSS, sanitization, workflow perms) - #3419

Merged
Marfuen merged 2 commits into
mainfrom
mariano/fix-codeql-alerts
Jul 15, 2026
Merged

Marfuen merged 2 commits into
mainfrom
mariano/fix-codeql-alerts

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Resolves the 6 open CodeQL code-scanning alerts.

#108 — DOM XSS (High, js/xss-through-dom) — the real one

preview.tsx (automation preview) assigned user-typed input straight to iframe.src and <a href>, so a value like javascript:alert(document.cookie) or data:text/html,... would execute in the preview context.
Fix: a toSafeUrl() validator that only passes http:/https: URLs; every URL sink (iframe src, anchor href, refresh, load-new-url) now goes through it, and invalid input shows an error instead of navigating. Also added rel="noopener noreferrer" to the external link.

#95 — Incomplete sanitization (High, js/incomplete-sanitization)

generate-task-types.ts (codegen) escaped single quotes but not backslashes when embedding task fields in single-quoted TS literals (a trailing \ or \' breaks out). department/frequency/id weren't escaped at all.
Fix: a sq() helper that escapes backslash-first, then quote, applied to id/name/department/frequency. (Codegen script, non-runtime, but now correct.)

#80 / #81 / #84 / #85 — Missing workflow permissions (Medium ×4)

The two Trigger.dev deploy + two DB-migration workflows had no permissions: block (inheriting broad default token scope).
Fix: top-level permissions: contents: read on each — they only check out to build/deploy/migrate, no repo writes.

Verification

  • ✅ app typecheck: 0 errors in preview.tsx (remaining are pre-existing test-file debt)
  • ✅ codegen script typechecks
  • ✅ all 4 workflow YAMLs valid, permissions: {contents: read}
  • No library source patched; no untrusted input introduced into workflows.

Closes CodeQL #108, #95, #80, #81, #84, #85 (on next scan of main after merge).

🤖 Generated with Claude Code


Summary by cubic

Fixes 6 CodeQL alerts by blocking unsafe URLs in the automation preview, fixing string escaping in codegen, and restricting GitHub Actions permissions. Also drives preview navigation through state to keep links/refresh in sync and avoid double loads.

  • Bug Fixes
    • DOM XSS: Added http(s)-only toSafeUrl() and used it for iframe src, anchor href, refresh, and load; invalid input shows an error; added rel="noopener noreferrer"; navigation now goes through state so the external link, refresh, and retry match the shown URL and don’t double-load.
    • Codegen sanitization: Introduced sq() to escape backslash first, then quote; applied to id, name, department, frequency; kept template literal description with backslash-first escaping.
    • GitHub Actions: Added permissions: contents: read to the two deploy and two database migration workflows.

Written for commit e0690fb. Summary will update on new commits.

Review in cubic

…w perms)

- #108 (high, js/xss-through-dom): preview.tsx assigned user-typed input to
  iframe.src / anchor href, allowing javascript:/data: URIs to execute in the
  preview context. Gate every URL sink through an http(s)-only validator.
- #95 (high, js/incomplete-sanitization): generate-task-types.ts escaped single
  quotes but not backslashes when embedding task fields in single-quoted TS
  string literals. Add a helper that escapes backslash-first and apply it to
  id/name/department/frequency.
- #80/#81/#84/#85 (medium, actions/missing-workflow-permissions): the two
  Trigger.dev deploy + two DB-migration workflows had no permissions block.
  Add top-level 'permissions: contents: read' (they only check out to build/
  deploy/migrate — no repo writes).

Verified: app typecheck clean for preview.tsx; codegen script typechecks;
all 4 workflow YAMLs valid.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 5:05pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 5:05pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
portal Skipped Skipped Jul 15, 2026 5:05pm

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files

Confidence score: 5/5

  • Safe to merge after the addressed issues were fixed.

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

loadNewUrl navigated the iframe imperatively (iframeRef.current.src) without
updating currentUrl, so the external-link href, refresh, and try-again all
referred to the stale previous URL. Drive navigation through setCurrentUrl
instead (the iframe src prop follows currentUrl/safeUrl), keeping every URL
consumer in sync with what's shown — and avoiding a double-load from setting
both iframe.src and the src prop. Same-URL entries still go through
refreshIframe's cache-bust.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel
vercel Bot temporarily deployed to Preview – portal July 15, 2026 17:02 Inactive
@Marfuen
Marfuen merged commit 32329be into main Jul 15, 2026
11 checks passed
@Marfuen
Marfuen deleted the mariano/fix-codeql-alerts branch July 15, 2026 17:12
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

2 active and 1 inactive deployments
Preview – app — e0690fbf Deployed Jul 15, 2026 by vercel[bot]
Preview – comp-framework-editor — e0690fbf Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — e0690fbf Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants