A bare <img> in a rendered email body wasn't wrapped in any link, so the
only way to see it full-size was the browser's right-click "open image in
new tab". sanitizeEmailHtml now wraps every image that isn't already inside
a real link (a sender-linked banner is left alone, no double-wrapping) in
<a href={its own src} target="_blank" rel="noopener noreferrer"> — a normal
left click, middle click, or ctrl-click all now do the expected thing.
The wrapping step (lib/mail/sanitize-html.ts, using the new cheerio dep)
builds the <a> via .attr() rather than string-interpolating the src into an
HTML template — sanitize-html only validates an img src's URL *scheme*, not
that a data: URI's declared content is actually image data, so a crafted
src could otherwise contain characters that break out of an attribute if
naively concatenated into HTML text for re-parsing. Covered by 3 new tests
in sanitize-html.test.ts, including that exact injection attempt.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GteWhnWKTmnXcsd5jx6H7u
56 lines
1.5 KiB
JSON
56 lines
1.5 KiB
JSON
{
|
|
"name": "top-tickets",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"scripts": {
|
|
"dev": "next dev",
|
|
"build": "next build",
|
|
"start": "next start -p ${PORT:-8081}",
|
|
"lint": "eslint",
|
|
"test": "vitest run",
|
|
"db:generate": "drizzle-kit generate",
|
|
"db:migrate": "drizzle-kit migrate",
|
|
"generate-key": "tsx scripts/generate-key.ts",
|
|
"bootstrap-admin": "tsx scripts/bootstrap-admin.ts"
|
|
},
|
|
"dependencies": {
|
|
"argon2": "^0.45.1",
|
|
"better-sqlite3": "^12.11.1",
|
|
"cheerio": "^1.2.0",
|
|
"drizzle-orm": "^0.45.2",
|
|
"framer-motion": "^12.4.7",
|
|
"html-to-text": "^10.0.0",
|
|
"imapflow": "^1.5.0",
|
|
"ldapjs": "^3.0.7",
|
|
"lucide-react": "^0.545.0",
|
|
"mailparser": "^3.9.14",
|
|
"next": "16.2.12",
|
|
"nodemailer": "^9.0.3",
|
|
"react": "19.2.4",
|
|
"react-dom": "19.2.4",
|
|
"sanitize-html": "^2.13.1",
|
|
"telegraf": "^4.16.3",
|
|
"web-push": "^3.6.7",
|
|
"zod": "^4.4.3"
|
|
},
|
|
"devDependencies": {
|
|
"@tailwindcss/postcss": "^4.1.16",
|
|
"@types/better-sqlite3": "^7.6.13",
|
|
"@types/ldapjs": "^3.0.6",
|
|
"@types/mailparser": "^3.4.6",
|
|
"@types/node": "^20",
|
|
"@types/nodemailer": "^8.0.1",
|
|
"@types/react": "^19",
|
|
"@types/react-dom": "^19",
|
|
"@types/sanitize-html": "^2.16.1",
|
|
"@types/web-push": "^3.6.4",
|
|
"drizzle-kit": "^0.31.10",
|
|
"eslint": "^9",
|
|
"eslint-config-next": "16.2.12",
|
|
"tailwindcss": "^4.1.16",
|
|
"tsx": "^4.23.1",
|
|
"typescript": "^5",
|
|
"vitest": "^3.2.7"
|
|
}
|
|
}
|