Skip to content

Potential fix for code scanning alert no. 1824: DOM text reinterpreted as HTML - #5077

Open
ajay-dhangar wants to merge 1 commit into
mainfrom
alert-autofix-1824
Open

ajay-dhangar wants to merge 1 commit into
mainfrom
alert-autofix-1824

Conversation

@ajay-dhangar

Copy link
Copy Markdown
Member

Potential fix for https://github.com/codeharborhub/codeharborhub.github.io/security/code-scanning/1824

To fix this without changing intended functionality, avoid embedding untrusted CSS directly into an HTML string passed to document.write. Instead:

  1. Write a static/safe HTML skeleton to the iframe.
  2. Create a <style> element via DOM APIs.
  3. Assign user CSS to styleEl.textContent (not innerHTML and not template-interpolated HTML).
  4. Append the style element to the iframe document head.

This preserves CSS preview behavior while preventing </style>... breakout attacks, since textContent is treated as plain text within the style node.

In src/components/CodePlayground.jsx, update only the executeCSS function region (lines around 106–129). Replace the dynamic htmlContent template usage and iframeDoc.write(htmlContent) with safe document construction and stylesheet injection via textContent. No new imports or dependencies are needed.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…d as HTML

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@ajay-dhangar
ajay-dhangar marked this pull request as ready for review September 23, 2026 03:51

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great job, @ajay-dhangar! 🎉 Thank you for submitting your pull request to CodeHarborHub. We appreciate your contribution and enthusiasm! Our team will review it soon. If you have any questions or need further assistance, feel free to reach out. Thanks for contributing!

@deepsource-io

deepsource-io Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

DeepSource Code Review

We reviewed changes in 081cf5e...580c06f on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Sep 23, 2026 3:51a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@github-actions

Copy link
Copy Markdown

⚡️ Lighthouse Report for the Deploy Preview of this PR 🚀

🔗 Site: CodeHarborHub | Live Site

URL 🌐 Performance Accessibility Best Practices SEO 📊
/ 🔴 28 🟡 88 🟡 75 🟢 100 📄
/docs 🔴 49 🟡 87 🟡 75 🟢 100 📄
/courses 🟡 57 🟢 91 🟡 75 🟢 100 📄
/showcase 🟡 52 🟡 87 🟡 75 🟡 86 📄
/community 🟡 54 🟡 86 🟡 75 🟢 100 📄

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant