fix(security): harden YAML parsing, path traversal, and markdown links

- workflowSerialization: restrict YAML parser to core schema with no custom tags
- gitService: validate file paths stay within project directory before I/O
- chatMarkdown: allowlist URL protocols (https, http, mailto, anchors)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
David Kaya
2026-04-05 23:43:06 +02:00
co-authored by Copilot
parent b302ea5979
commit 059714326a
3 changed files with 26 additions and 5 deletions
+6 -1
View File
@@ -100,10 +100,15 @@ export const chatMarkdownComponents: Components = {
},
a({ href, children }) {
const url = String(href ?? '');
const isSafe = /^https?:|^mailto:|^#/i.test(url);
if (!isSafe) {
return <span className="text-indigo-400">{children as ReactNode}</span>;
}
return (
<a
className="text-indigo-400 underline underline-offset-2 transition hover:text-indigo-300"
href={String(href)}
href={url}
rel="noopener noreferrer"
target="_blank"
>