|
sanitization, vendored DataTables exclusion)
Remediates all 11 open CodeQL alerts on the default branch:
- version-picker.js (js/xss-through-dom, alerts 1-3): percent-encode every
DOM-derived path component (select.value, parsed location segments) at URL
construction time via encodePath()/langUrlFor(), and tighten the
parseLocation slug charset to [A-Za-z0-9._-]. No-op on legitimate sphinx
slugs — URLs stay byte-identical (asserted by tests).
- workers/apex/test/manifest.test.ts (js/incomplete-multi-character-
sanitization, alert 6): strip HTML comments from the root.html fixture
repeatedly to a fixpoint instead of a single pass.
- docs/_static/js/datatables.js (alerts 4,5,7-11): excluded from CodeQL
analysis via .github/codeql/codeql-config.yml (new codeql-cfg-path input
to the fleet reusable workflow). The file is vendored stock DataTables
1.11.5; the flagged helpers are display/sort normalization, not
sanitization boundaries. Excluding keeps the vendored copy byte-identical
to upstream instead of hand-patching it.
Adds 9 picker tests (hostile-input encoding + slug-charset accept/reject);
workers suite 103/103 green.
🤖 Generated by [robots](https://vyos.io)
|