Summary
EmbedPreview.generateSnippet interpolates apiId directly into the iframe src URL and title attribute. An id containing quotes or '&' yields broken or injectable HTML that users paste into their own sites.
Why this matters
The snippet is copied into third-party pages; attribute injection there becomes a stored XSS vector on the embedding site.
Scope
encodeURIComponent the id in the URL and HTML-escape it in the title attribute; add tests with quotes and angle brackets.
Relevant code in CalloraOrg/Callora-Frontend:
src/components/EmbedPreview.tsx
Priority
Medium
Acceptance criteria
- The src URL uses an encoded id
- The title attribute escapes quotes and angle brackets
- Normal ids render unchanged
- EmbedPreview tests cover hostile ids
Validation
npm test -- --run src/components/EmbedPreview.test.tsx
Non-goals
- Typo-only, formatting-only, or cosmetic changes.
- Unrelated refactors, dependency upgrades, or broad rewrites.
- Removing safeguards or weakening validation to make tests pass.
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.
Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code
Summary
EmbedPreview.generateSnippet interpolates apiId directly into the iframe src URL and title attribute. An id containing quotes or '&' yields broken or injectable HTML that users paste into their own sites.
Why this matters
The snippet is copied into third-party pages; attribute injection there becomes a stored XSS vector on the embedding site.
Scope
encodeURIComponent the id in the URL and HTML-escape it in the title attribute; add tests with quotes and angle brackets.
Relevant code in CalloraOrg/Callora-Frontend:
src/components/EmbedPreview.tsxPriority
Medium
Acceptance criteria
Validation
npm test -- --run src/components/EmbedPreview.test.tsx
Non-goals
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include
Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code