mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 10:23:14 +00:00
* fix: render GitHub-hosted images in PR descriptions on reviews page PR description images hosted on GitHub (user-attachment uploads and *.githubusercontent.com) render broken on the reviews page because private-repo attachments require GitHub auth the browser session lacks. Add an authenticated backend image proxy (host-allowlisted to guard against SSRF) and route those image URLs through it from the reviews UI. Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> * fix: harden PR image proxy (IDOR, SVG XSS, unbounded buffering) Address review findings on the review-page image proxy: - IDOR: the proxy fetched any *.githubusercontent.com URL with the App installation token, gated only by route-param repo access, so a user authorized for one repo could read images from another private repo the App can see. Bind the URL to the authorized PR — only proxy URLs that appear in that PR's body. - SVG XSS: served any image/* inline from the API origin, including image/svg+xml which can run script. Restrict to safe raster types and add X-Content-Type-Options: nosniff + a locked-down CSP. - DoS: enforced the size cap only after buffering the full response. Stream and abort once the cap is exceeded. --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| assets | ||
| public | ||
| src | ||
| .cta.json | ||
| .gitignore | ||
| .prettierignore | ||
| .prettierrc | ||
| bun.lock | ||
| components.json | ||
| eslint.config.js | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
| vercel.json | ||
| vite.config.ts | ||
| yarn.lock | ||
TanStack Start + shadcn/ui
This is a template for a new TanStack Start project with React, TypeScript, and shadcn/ui.
Adding components
To add components to your app, run the following command:
npx shadcn@latest add button
This will place the ui components in the components directory.
Using components
To use the components in your app, import them as follows:
import { Button } from "@/components/ui/button";