feat: Update version to 3.0.5 and enhance CustomBranding with new search form functionality and improved styling

This commit is contained in:
Torsten Brendgen
2026-08-19 23:33:56 +02:00
parent 36bcef54e7
commit 281dfa68de
13 changed files with 353 additions and 60 deletions
+23 -6
View File
@@ -1,4 +1,4 @@
/* CustomBranding 2.0.0 - safe Classic SharePoint runtime */
/* CustomBranding 3.0.5 - safe Classic SharePoint runtime */
(function (global) {
'use strict';
@@ -6,7 +6,7 @@
var OWNER = 'CustomBranding.Classic';
var MAX_DEPTH = 8;
var MAX_ELEMENTS = 200;
var allowedTags = ['div', 'span', 'p', 'a', 'button', 'img', 'h1', 'h2', 'h3', 'strong', 'em', 'nav', 'section'];
var allowedTags = ['div', 'span', 'p', 'a', 'button', 'form', 'input', 'img', 'h1', 'h2', 'h3', 'strong', 'em', 'nav', 'section'];
var allowedStyles = ('align-items background background-color border border-bottom border-color border-left border-radius border-right border-style border-top border-width box-sizing color display flex flex-basis flex-direction flex-grow flex-shrink flex-wrap font-family font-size font-style font-weight gap grid-template-columns height justify-content line-height margin margin-bottom margin-left margin-right margin-top max-height max-width min-height min-width opacity overflow padding padding-bottom padding-left padding-right padding-top text-align text-decoration text-transform white-space width').split(' ');
var state = { debug: false, hosts: [], css: [] };
@@ -78,6 +78,8 @@
if (tag === 'a') { return ['href', 'target'].indexOf(name) >= 0; }
if (tag === 'img') { return ['src', 'alt', 'width', 'height'].indexOf(name) >= 0; }
if (tag === 'button') { return ['type', 'disabled', 'aria-expanded', 'aria-controls'].indexOf(name) >= 0; }
if (tag === 'form') { return ['action', 'method'].indexOf(name) >= 0; }
if (tag === 'input') { return ['type', 'name', 'placeholder', 'autocomplete', 'maxlength'].indexOf(name) >= 0; }
return false;
}
@@ -94,11 +96,23 @@
var name = String(rawName).toLowerCase();
var value = String(attributes[rawName] === undefined ? '' : attributes[rawName]).substring(0, 2048);
if (name.indexOf('on') === 0 || !allowedAttribute(tag, name)) { continue; }
if (name === 'href' || name === 'src') {
if (name === 'href' || name === 'src' || name === 'action') {
var safeUrl = sanitizeUrl(value, name === 'href');
if (safeUrl) { element.setAttribute(name, safeUrl); }
if (safeUrl && safeUrl.indexOf('//') !== 0) { element.setAttribute(name, safeUrl); }
} else if (name === 'target') {
if (value === '_blank' || value === '_self') { element.setAttribute(name, value); }
} else if (name === 'type' && tag === 'button') {
element.setAttribute('type', value.toLowerCase() === 'submit' ? 'submit' : 'button');
} else if (name === 'type' && tag === 'input') {
element.setAttribute('type', 'search');
} else if (name === 'method' && tag === 'form') {
element.setAttribute('method', 'get');
} else if (name === 'name' && tag === 'input') {
if (/^[a-z0-9_-]{1,64}$/i.test(value)) { element.setAttribute('name', value); }
} else if (name === 'autocomplete' && tag === 'input') {
if (value === 'on' || value === 'off') { element.setAttribute('autocomplete', value); }
} else if (name === 'maxlength' && tag === 'input') {
if (/^\d{1,4}$/.test(value)) { element.setAttribute('maxlength', value); }
} else if ((name === 'id' || name === 'class') && !/^[a-z0-9 _-]{1,256}$/i.test(value)) {
continue;
} else if ((name === 'width' || name === 'height') && !/^\d{1,4}$/.test(value)) {
@@ -109,7 +123,10 @@
if (name === 'alt') { hasAlt = true; }
}
if (tag === 'img' && !hasAlt) { return null; }
if (tag === 'button') { element.setAttribute('type', 'button'); }
if (tag === 'form' && !element.getAttribute('action')) { return null; }
if (tag === 'form') { element.setAttribute('method', 'get'); }
if (tag === 'input') { element.setAttribute('type', 'search'); element.setAttribute('name', element.getAttribute('name') || 'q'); }
if (tag === 'button' && element.getAttribute('type') !== 'submit') { element.setAttribute('type', 'button'); }
if (tag === 'a' && element.getAttribute('target') === '_blank') { element.setAttribute('rel', 'noopener noreferrer'); }
var styles = config.styles && typeof config.styles === 'object' ? config.styles : {};
@@ -121,7 +138,7 @@
if (config.content !== undefined && config.content !== null) {
element.appendChild(document.createTextNode(String(config.content).substring(0, 4000)));
}
if (tag !== 'img' && Array.isArray(config.children)) {
if (tag !== 'img' && tag !== 'input' && Array.isArray(config.children)) {
for (var i = 0; i < config.children.length; i++) {
var child = createElement(config.children[i], depth + 1, counter);
if (child) { element.appendChild(child); }