Wiki Phase 1: categories, drafts/publish, HTML sanitization
Foundation & safety phase of the wiki upgrade (see WIKI_UPGRADE.md). Schema (additive, idempotent via ensureSchema): - new wiki_categories table; wiki_pages gains category_id, excerpt, published, published_at, sort_order, and a FULLTEXT index - migration ALTERs guarded with IF NOT EXISTS for existing databases - seed reworked into 4 sections with the 8 starter pages assigned Security: - new utils/sanitizeHtml.js (sanitize-html allowlist); wiki bodies are sanitized on every save, and the article renders through DOMPurify - strips <script>, event handlers (onerror), and javascript: URLs Backend: - public: published-only list with ?category filter + /wiki/categories - admin: extended page CRUD, PATCH publish toggle, category CRUD; drafts visible to admin, hidden from public - all writes logged to activity_log Frontend: - data-driven public wiki index (sections + real descriptions; removed hardcoded blurbs/Roman numerals) with ?category filtering - article: category breadcrumb + sanitized render - admin: Section/Status columns, draft/publish + section + excerpt in the editor, and a Manage sections modal Verified end-to-end against MariaDB 11: migration clean, XSS neutralized, drafts hidden, client builds, server boots. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -9,7 +9,12 @@
|
||||
"seed": "node db/seed.js",
|
||||
"test": "echo \"no tests yet\" && exit 0"
|
||||
},
|
||||
"keywords": ["express", "mariadb", "jwt", "bcrypt"],
|
||||
"keywords": [
|
||||
"express",
|
||||
"mariadb",
|
||||
"jwt",
|
||||
"bcrypt"
|
||||
],
|
||||
"author": "whitlocktech",
|
||||
"license": "ISC",
|
||||
"dependencies": {
|
||||
@@ -25,7 +30,8 @@
|
||||
"mariadb": "^3.3.1",
|
||||
"morgan": "^1.10.0",
|
||||
"multer": "^2.0.1",
|
||||
"nodemailer": "^9.0.1"
|
||||
"nodemailer": "^9.0.1",
|
||||
"sanitize-html": "^2.17.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"nodemon": "^3.1.4"
|
||||
|
||||
Reference in New Issue
Block a user