Skip to content

#6282 Re-audit source and sinks - #6283

Merged
sosnovsky merged 3 commits into
masterfrom
issue-6282-review-source-and-sinks
Aug 31, 2026
Merged

#6282 Re-audit source and sinks#6283
sosnovsky merged 3 commits into
masterfrom
issue-6282-review-source-and-sinks

Conversation

@martgil

@martgil martgil commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

This PR re-audit and improve source and sinks.

close #6282


Tests (delete all except exactly one):

  • Does not need tests (refactor only, docs or internal changes)

To be filled by reviewers

I have reviewed that this PR... (tick whichever items you personally focused on during this review):

  • addresses the issue it closes (if any)
  • code is readable and understandable
  • is accompanied with tests, or tests are not needed
  • is free of vulnerabilities
  • is documented clearly and usefully, or doesn't need documentation

@martgil
martgil requested a review from sosnovsky as a code owner August 27, 2026 06:50
@martgil
martgil marked this pull request as draft August 27, 2026 10:39
Comment thread extension/chrome/elements/attachment.ts
Comment thread extension/chrome/elements/compose-modules/compose-quote-module.ts
@martgil
martgil marked this pull request as ready for review August 28, 2026 13:11
@martgil
martgil requested a review from sosnovsky August 28, 2026 13:11
@martgil

martgil commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator Author

Hi @sosnovsky - This one is ready for a review again. Thanks!

@sosnovsky sosnovsky left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

all good now 👍

@sosnovsky
sosnovsky merged commit e605f9c into master Aug 31, 2026
12 checks passed
@sosnovsky
sosnovsky deleted the issue-6282-review-source-and-sinks branch August 31, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Audit HTML sinks across the codebase for missing input sanitization

2 participants