Prevent csv export injections (#14347)

**Small Security Issue:** CSV exports were vulnerable to formula
injection attacks when users entered values starting with =, +, -, or @.
(only happens if a logged-in user injects corrupted data)

Solution:
- Added ZWJ (Zero-Width Joiner) protection that prefixes dangerous
values with invisible Unicode character
- This is the best way to preserve original data while preventing Excel
from executing formulas
- Added import cleanup to restore original values when re-importing
 
Changes:
- New sanitizeValueForCSVExport() function for security
- Updated all CSV export paths to use both security + formatting
functions
- Added comprehensive tests covering attack vectors and international
characters
- Also added cursor rules for better code consistency

---------

Co-authored-by: Charles Bochet <charlesBochet@users.noreply.github.com>
This commit is contained in:
Félix Malfait
2025-09-08 17:57:46 +02:00
committed by GitHub
parent 374b5dce66
commit cebcf4f1f5
293 changed files with 1847 additions and 1399 deletions
@@ -24,8 +24,6 @@ export {
getLogoUrlFromDomainName,
} from './image/getLogoUrlFromDomainName';
export { getUniqueConstraintsFields } from './indexMetadata/getUniqueConstraintsFields';
export { getAppPath } from './navigation/getAppPath';
export { getSettingsPath } from './navigation/getSettingsPath';
export { parseJson } from './parseJson';
export { removePropertiesFromRecord } from './removePropertiesFromRecord';
export { removeUndefinedFields } from './removeUndefinedFields';
@@ -1,110 +0,0 @@
import { AppPath } from '../../../types';
import { getAppPath } from '../getAppPath';
describe('getAppPath', () => {
it('should return path as-is when no params or query params provided', () => {
expect(getAppPath(AppPath.Index)).toBe('/');
expect(getAppPath(AppPath.TasksPage)).toBe('/objects/tasks');
expect(getAppPath(AppPath.SignInUp)).toBe('/welcome');
});
it('should generate path with params using react-router generatePath', () => {
expect(
getAppPath(AppPath.RecordIndexPage, {
objectNamePlural: 'companies',
}),
).toBe('/objects/companies');
expect(
getAppPath(AppPath.RecordShowPage, {
objectNameSingular: 'company',
objectRecordId: '123',
}),
).toBe('/object/company/123');
expect(
getAppPath(AppPath.Invite, {
workspaceInviteHash: 'abc123',
}),
).toBe('/invite/abc123');
});
it('should append query params when provided', () => {
expect(
getAppPath(AppPath.Index, undefined, {
filter: 'active',
sort: 'name',
}),
).toBe('/?filter=active&sort=name');
expect(
getAppPath(AppPath.TasksPage, undefined, {
view: 'kanban',
}),
).toBe('/objects/tasks?view=kanban');
});
it('should handle both params and query params together', () => {
expect(
getAppPath(
AppPath.RecordIndexPage,
{ objectNamePlural: 'companies' },
{ filter: 'active', view: 'table' },
),
).toBe('/objects/companies?filter=active&view=table');
expect(
getAppPath(
AppPath.RecordShowPage,
{ objectNameSingular: 'company', objectRecordId: '123' },
{ tab: 'details' },
),
).toBe('/object/company/123?tab=details');
});
it('should filter out null and undefined values from query params', () => {
expect(
getAppPath(AppPath.Index, undefined, {
filter: 'active',
sort: null,
view: undefined,
limit: '10',
}),
).toBe('/?filter=active&limit=10');
});
it('should handle empty query params object', () => {
expect(getAppPath(AppPath.Index, undefined, {})).toBe('/');
});
it('should handle query params with only null/undefined values', () => {
expect(
getAppPath(AppPath.Index, undefined, {
filter: null,
sort: undefined,
}),
).toBe('/');
});
it('should handle complex query param values', () => {
expect(
getAppPath(AppPath.Index, undefined, {
filters: JSON.stringify({ status: 'active' }),
array: ['value1', 'value2'],
number: 42,
boolean: true,
}),
).toBe(
'/?filters=%7B%22status%22%3A%22active%22%7D&array%5B0%5D=value1&array%5B1%5D=value2&number=42&boolean=true',
);
});
it('should handle special characters in query params', () => {
expect(
getAppPath(AppPath.Index, undefined, {
search: 'test & query',
email: 'user@example.com',
}),
).toBe('/?search=test%20%26%20query&email=user%40example.com');
});
});
@@ -1,148 +0,0 @@
import { SettingsPath } from '../../../types';
import { getSettingsPath } from '../getSettingsPath';
describe('getSettingsPath', () => {
it('should return settings path with correct prefix when no params or query params provided', () => {
expect(getSettingsPath(SettingsPath.ProfilePage)).toBe('/settings/profile');
expect(getSettingsPath(SettingsPath.Workspace)).toBe('/settings/general');
expect(getSettingsPath(SettingsPath.Accounts)).toBe('/settings/accounts');
});
it('should generate path with params using react-router generatePath', () => {
expect(
getSettingsPath(SettingsPath.ObjectDetail, {
objectNamePlural: 'companies',
}),
).toBe('/settings/objects/companies');
expect(
getSettingsPath(SettingsPath.ObjectFieldEdit, {
objectNamePlural: 'companies',
fieldName: 'name',
}),
).toBe('/settings/objects/companies/name');
expect(
getSettingsPath(SettingsPath.ServerlessFunctionDetail, {
serverlessFunctionId: 'func123',
}),
).toBe('/settings/functions/func123');
expect(
getSettingsPath(SettingsPath.EditImapSmtpCaldavConnection, {
connectedAccountId: 'account123',
}),
).toBe('/settings/accounts/edit-imap-smtp-caldav-connection/account123');
});
it('should append query params when provided', () => {
expect(
getSettingsPath(SettingsPath.ProfilePage, undefined, {
tab: 'personal',
edit: 'true',
}),
).toBe('/settings/profile?tab=personal&edit=true');
expect(
getSettingsPath(SettingsPath.Objects, undefined, {
view: 'list',
}),
).toBe('/settings/objects?view=list');
});
it('should append hash when provided', () => {
expect(
getSettingsPath(
SettingsPath.ProfilePage,
undefined,
undefined,
'section1',
),
).toBe('/settings/profile#section1');
expect(
getSettingsPath(SettingsPath.Workspace, undefined, undefined, 'general'),
).toBe('/settings/general#general');
});
it('should handle hash with leading # character', () => {
expect(
getSettingsPath(
SettingsPath.ProfilePage,
undefined,
undefined,
'#section1',
),
).toBe('/settings/profile#section1');
});
it('should handle params, query params, and hash together', () => {
expect(
getSettingsPath(
SettingsPath.ObjectDetail,
{ objectNamePlural: 'companies' },
{ tab: 'fields', edit: 'true' },
'advanced',
),
).toBe('/settings/objects/companies?tab=fields&edit=true#advanced');
expect(
getSettingsPath(
SettingsPath.ServerlessFunctionDetail,
{ serverlessFunctionId: 'func123' },
{ mode: 'edit' },
'code',
),
).toBe('/settings/functions/func123?mode=edit#code');
});
it('should filter out null and undefined values from query params', () => {
expect(
getSettingsPath(SettingsPath.ProfilePage, undefined, {
tab: 'personal',
edit: null,
view: undefined,
active: 'true',
}),
).toBe('/settings/profile?tab=personal&active=true');
});
it('should handle empty query params object', () => {
expect(getSettingsPath(SettingsPath.ProfilePage, undefined, {})).toBe(
'/settings/profile',
);
});
it('should handle query params with only null/undefined values', () => {
expect(
getSettingsPath(SettingsPath.ProfilePage, undefined, {
tab: null,
edit: undefined,
}),
).toBe('/settings/profile');
});
it('should handle complex query param values', () => {
expect(
getSettingsPath(SettingsPath.Objects, undefined, {
filters: JSON.stringify({ type: 'custom' }),
sort: ['name', 'created'],
page: 1,
enabled: true,
}),
).toBe(
'/settings/objects?filters=%7B%22type%22%3A%22custom%22%7D&sort%5B0%5D=name&sort%5B1%5D=created&page=1&enabled=true',
);
});
it('should handle special characters in query params', () => {
expect(
getSettingsPath(SettingsPath.ProfilePage, undefined, {
search: 'test & query',
email: 'user@example.com',
}),
).toBe(
'/settings/profile?search=test%20%26%20query&email=user%40example.com',
);
});
});
@@ -1,30 +0,0 @@
import qs from 'qs';
import { generatePath, type PathParam } from 'react-router-dom';
import { type AppPath } from '../../types';
import { isDefined } from '../validation';
export const getAppPath = <T extends AppPath>(
to: T,
params?: { [key in PathParam<T>]: string | null },
queryParams?: Record<string, any>,
) => {
let path: string = to;
if (isDefined(params)) {
path = generatePath<T>(to, params);
}
if (isDefined(queryParams)) {
const filteredParams = Object.fromEntries(
Object.entries(queryParams).filter(([_, value]) => isDefined(value)),
);
const queryString = qs.stringify(filteredParams);
if (queryString !== '') {
path += `?${queryString}`;
}
}
return path;
};
@@ -1,40 +0,0 @@
import qs from 'qs';
import { generatePath, type PathParam } from 'react-router-dom';
import { AppPath, type SettingsPath } from '../../types';
import { isDefined } from '../validation';
export const getSettingsPath = <T extends SettingsPath>(
to: T,
params?: {
[key in PathParam<`/${AppPath.Settings}/${T}`>]: string | null;
},
queryParams?: Record<string, any>,
hash?: string,
) => {
let path = `/${AppPath.Settings}/${to}`;
if (isDefined(params)) {
path = generatePath<`/${AppPath.Settings}/${T}`>(
`/${AppPath.Settings}/${to}`,
params,
);
}
if (isDefined(queryParams)) {
const filteredParams = Object.fromEntries(
Object.entries(queryParams).filter(([_, value]) => isDefined(value)),
);
const queryString = qs.stringify(filteredParams);
if (queryString !== '') {
path += `?${queryString}`;
}
}
if (isDefined(hash)) {
path += `#${hash.replace(/^#/, '')}`;
}
return path;
};