Skip to content

Conversation

@cmdcolin
Copy link
Contributor

This PR fixes an XSS reported by USDA ARS where track labels contain arbitrary non-sanitized HTML

We now use our 'sanitized' HTML

There might be some cases where users customized advanced track labels with arbitrary HTML but simple HTML should still work

This also has two rider changes

(a) vendors dojo-webpack-plugin, so it can be used on modern node.js versions
(b) uses webpack-dev-server instead of requiring users to run both yarn start and yarn watch

@cmdcolin cmdcolin merged commit 20907e3 into master Jan 20, 2026
1 check passed
@cmdcolin cmdcolin deleted the xss_fix branch January 20, 2026 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants