Skip to content

fix(security): sanitize unescaped HTML interpolation in certificate download (#489) - #524

Closed
Ranjeet2063 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
Ranjeet2063:fix/credential-xss-sanitize-489
Closed

Ranjeet2063 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
Ranjeet2063:fix/credential-xss-sanitize-489

Conversation

@Ranjeet2063

Copy link
Copy Markdown

Closes #489

Summary & Security Invariant Resolution

Resolves a potential Cross-Site Scripting (XSS) vulnerability during certificate export and download in src/app/credentials/[credentialId]/page.tsx.

Previously, handleDownload interpolated dynamic certificate fields directly into an HTML template string without escaping, which allowed unescaped HTML/JavaScript in course titles or metadata to execute when the downloaded certificate was opened in a user browser.

Changes Implemented

  1. HTML Sanitization Utility (htmlEscape):
    • Added and exported a dedicated htmlEscape helper function converting special characters (&, <, >, ", ') into their corresponding HTML entities (&amp;, &lt;, &gt;, &quot;, &#39;).
    • Safely handles null, undefined, and numeric values.
  2. Sanitized All Dynamic Certificate Template Interpolations:
    • Escaped credential.courseTitle in both <title> and <h2> elements.
    • Escaped formatted issuance date formatDate(credential.issuedAt).
    • Escaped credential.id.
    • Escaped truncateAddress(credential.tokenId, 8).
    • Escaped credential.metadata.score in the score badge display.
  3. Preserved Strict Issue Scope:
    • Exclusively confined modifications to src/app/credentials/[credentialId]/page.tsx with zero unrelated diffs.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 07:25
@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for chainlearn failed.

Name Link
🔨 Latest commit a17c118
🔍 Latest deploy log https://app.netlify.com/projects/chainlearn/deploys/6abe0afb3009490008ced96e

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@DeFiVC DeFiVC closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Certificate download has XSS vulnerability via unescaped HTML interpolation

3 participants