Skip to content
Prev Previous commit
Add XSS regression tests for annotations and legend text
sanitizeMathJaxLinks already covers these paths since it's applied
inside the shared convertToTspans, but only hover/title had explicit
coverage. Requested by @archmoj on PR #8051.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
  • Loading branch information
SergeyAxiomatic and claude committed Sep 21, 2026
commit dd5e7c7b2837a7e20e86e409c3fe3089709a1d98
41 changes: 41 additions & 0 deletions test/jasmine/bundle_tests/mathjax_test.js
Comment thread
SergeyAxiomatic marked this conversation as resolved.
Original file line number Diff line number Diff line change
Expand Up @@ -227,6 +227,47 @@ describe('Test MathJax v' + mathjaxVersion + ':', function() {
})
.then(done, done.fail);
});

it('should strip a javascript: url from a tex \\href in an annotation', function(done) {
Plotly.newPlot(gd, {
data: [{x: [1, 2, 3], y: [1, 2, 3]}],
layout: {
annotations: [{
x: 2,
y: 2,
showarrow: false,
text: '$\\href{javascript:alert(1)}{unsafe}$'
}]
}
})
.then(function() {
var gd3 = d3Select(gd);
var link = gd3.select('.annotation-text-math-group a');

expect(link.size()).toBe(1, 'annotation link exists');
expect(link.attr('href')).toBe(null, 'javascript: url stripped');
})
.then(done, done.fail);
});

it('should strip a javascript: url from a tex \\href in non-hover legend text', function(done) {
Plotly.newPlot(gd, {
data: [{
x: [1, 2, 3],
y: [1, 2, 3],
name: '$\\href{javascript:alert(1)}{unsafe}$'
}],
layout: {showlegend: true}
})
.then(function() {
var gd3 = d3Select(gd);
var link = gd3.select('.legendtext-math-group a');

expect(link.size()).toBe(1, 'legend link exists');
expect(link.attr('href')).toBe(null, 'javascript: url stripped');
})
.then(done, done.fail);
});
});

describe('Test hover tex rendering:', function() {
Expand Down