Enhance security by adding DOMPurify comments in Vue components and updating path handling comments in server utilities to mitigate path traversal risks.

This commit is contained in:
Torsten Schulz (local)
2025-12-20 11:15:31 +01:00
parent e73d328139
commit fbdb6f6b6f
45 changed files with 129 additions and 46 deletions

View File

@@ -64,6 +64,7 @@ export default defineEventHandler(async (event) => {
} catch (error) {
// nosemgrep: javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring
// file is from readdir, not user input; error.message is safe
// nosemgrep: javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring
console.error(`Fehler beim Laden von ${file}:`, error.message)
}
}