Aktualisiere Versionsnummer auf 3.2.4 in README.md, package.json, package-lock.json und package-solution.json. Füge Validierungen für sichere Formular-Elemente in CustomBrandingSettingsProvider hinzu und erweitere Tests entsprechend.

This commit is contained in:
Torsten Brendgen
2026-08-19 23:37:08 +02:00
parent 457e58b54f
commit de250e5dbb
8 changed files with 44 additions and 9 deletions
+8
View File
@@ -64,6 +64,14 @@ assert(normalizedBranding.elements === undefined, 'Legacy-Root-Elemente werden n
const unsafeBranding: any = branding.createDefault(); // tslint:disable-line:no-any
unsafeBranding.placeholdertop.elements = [{ type: 'script', content: 'alert(1)' }, { type: 'a', attributes: { onclick: 'alert(1)', href: 'javascript:alert(1)' } }];
assert(branding.validate(unsafeBranding).length >= 3, 'Unsichere Branding-Elemente werden nicht erkannt.');
const searchBranding: any = branding.createDefault(); // tslint:disable-line:no-any
searchBranding.placeholdertop.elements = [{
type: 'form', attributes: { action: '~sitecollection/_layouts/15/search.aspx/siteall', method: 'get' },
children: [{ type: 'input', attributes: { type: 'search', name: 'q' } }]
}];
assert(branding.validate(searchBranding).length === 0, 'Sichere deklarative Suchformulare werden nicht akzeptiert.');
searchBranding.placeholdertop.elements[0].attributes.action = 'javascript:alert(1)';
assert(branding.validate(searchBranding).length > 0, 'Unsichere Formular-Actions werden nicht erkannt.');
const expiry: ISettingsProvider<any> = getSettingsProvider('expiryindicator'); // tslint:disable-line:no-any
const normalizedExpiry: any = expiry.normalize({ baseField: 'Invalid field', future: true }); // tslint:disable-line:no-any