mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-08-02 10:00:17 +05:30
security: harden CSP, add path traversal protection, improve accessibility
Security fixes: - Remove external CDN sources from CSP (cdn.jsdelivr.net, cdnjs.cloudflare.com) - Add path validation functions to prevent path traversal attacks - Block access to sensitive system directories - Add isPathAccessible() check for file operations UI/Accessibility fixes: - Increase tab close button from 16px to 24px for better touch targets - Add focus-visible styles for keyboard navigation - Add ARIA labels to all toolbar buttons - Add aria-hidden="true" to decorative SVG icons - Add role="tablist" and role="tab" to tab bar - Fix duplicate font-size declaration in .preview-content Reports generated: - Security vulnerability scan (10 findings) - STRIDE threat model with MITRE ATT&CK mapping - Comprehensive UI design review (40 issues) Amit Haridas
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
{
|
||||
"target": "MarkdownConverter Electron Application",
|
||||
"status": "in_progress",
|
||||
"depth": "comprehensive",
|
||||
"compliance_frameworks": ["owasp"],
|
||||
"current_step": 3,
|
||||
"current_phase": 1,
|
||||
"completed_steps": ["vulnerability-scan", "threat-modeling"],
|
||||
"files_created": ["01-vulnerability-scan.md", "02-threat-model.md"],
|
||||
"started_at": "2026-03-15T00:09:00.000Z",
|
||||
"last_updated": "2026-03-15T00:25:00.000Z",
|
||||
"findings_summary": {
|
||||
"critical": 2,
|
||||
"high": 3,
|
||||
"medium": 3,
|
||||
"low": 2,
|
||||
"total": 10
|
||||
},
|
||||
"fixes_applied": {
|
||||
"csp_external_cdns_removed": true,
|
||||
"path_traversal_protection_added": true,
|
||||
"aria_labels_added": true,
|
||||
"focus_visible_styles_added": true,
|
||||
"tab_close_button_resized": true,
|
||||
"duplicate_font_size_fixed": true
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user