[PM-38190] Improve sanitization of storybook args helper#21362
Conversation
🤖 Bitwarden Claude Code ReviewOverall Assessment: APPROVE Reviewed the sanitization hardening of the Storybook Code Review DetailsNo findings. The escaping order (backslash before single-quote, then HTML-entity escaping of the assembled expression) is correct, primitive |
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #21362 +/- ##
=======================================
Coverage 49.20% 49.20%
=======================================
Files 4071 4071
Lines 127744 127744
Branches 19551 19551
=======================================
Hits 62856 62856
Misses 60234 60234
Partials 4654 4654 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|



🎟️ Tracking
PM-38190
📔 Objective
This PR adds sanitization to the storybook args helper, which was previously possible to send XSS attacks through due to the way Storybook allows you to post messages that add story args. See linked vuln ticket for a more detailed writeup.