Skip to content

Security: codeverta/rich

Security

SECURITY.md

Security model

This library reduces browser content-injection risk. It cannot guarantee freedom from XSS or other attacks, and it cannot secure the application in which it is embedded. It has not received an independent penetration test.

Trust boundaries

Treat all initial, pasted, dropped, imported, persisted, and API-supplied content as untrusted. The component sanitizes HTML before parsing into the editor and on HTML export. Markdown is parsed and then sanitized. JSON import checks shape, primitive attributes, URL fields, equation length, depth, and node count, then serializes through the known schema and sanitizes the resulting HTML. Unknown JSON node/mark types are rejected by schema serialization. Arbitrary object-valued attributes are rejected.

The editor uses a schema rather than executing arbitrary document markup. DOMPurify uses explicit element and attribute allowlists. Script/style tags, event attributes, SVG/MathML input, embedded frames, arbitrary object/embed content, IDs, names, and arbitrary CSS are excluded. Only limited text-formatting CSS survives. Form input is limited to disabled checkboxes when exporting. KaTeX creates its own trusted rendering DOM from LaTeX with trust: false, strict mode, and macro-expansion/size limits. HTML-based LaTeX features are not trusted.

Links require explicit HTTP, HTTPS, mailto, or tel schemes and reject credentials/control characters. Images require HTTPS and reject inline data/SVG/blob URLs. The component does not fetch or proxy assets on the server. HTTPS does not guarantee an image host is trustworthy: images can track readers and leak their IP. Restrict image hosts with your CSP and/or a reviewed media service if necessary. New-window links receive noopener noreferrer nofollow.

Input and structural limits are defensive ceilings, not a proof against denial of service. Pathological HTML, complex LaTeX, huge paste transactions, and many table cells can still consume browser resources. For hostile multi-tenant documents, apply tighter limits and isolate expensive conversion services.

Host application requirements

  • Authenticate users and authorize every document read/write on the server. Read-only UI is not server authorization.
  • Validate and sanitize again on the server and at each HTML rendering sink. Browser validation can be bypassed entirely by an API caller. Use a current sanitizer compatible with your server's DOM implementation; do not blindly reuse browser helpers in Node.
  • Do not execute stored HTML, JSON attributes, Markdown HTML, or LaTeX as JavaScript. Do not mutate sanitized strings with untrusted substitutions after sanitization.
  • Protect cookie-authenticated writes against CSRF; validate request origin, body size, content type, and rate limits. Render text errors as text, not HTML.
  • Keep dependencies patched and monitor advisories. A clean npm audit only means the registry reported no known matching advisories at that moment.
  • When using onImageUpload: the client checks file size (5 MB), declared MIME type, extension, and file signature for PNG, JPEG, GIF, and WebP. These checks can be bypassed. The upload endpoint must validate actual decoded content and pixel limits, generate server-side filenames, reject executable/SVG content, authorize downloads, and serve media from an isolated origin. No upload backend is supplied here.
  • Avoid passing secrets into document content. Store drafts only using an explicit, authorized persistence policy. The supplied demo has no autosave.

CSP example

The demo contains a meta CSP for local use. A production host should enforce a response-header CSP, adapt image/connect sources to its actual integrations, and include frame-ancestors in the header (it is not enforceable by a meta CSP). Example baseline:

default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline';
img-src 'self' https:; font-src 'self'; connect-src 'self';
object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none';

Inline styles are used for rich-text formatting and KaTeX. Tighten allowed remote image hosts for your use case. Development HMR additionally needs the local WebSocket endpoint. The library ships KaTeX CSS separately; use your bundler's font output policy and adjust CSP if it inlines fonts.

Validation and reporting

Automated regressions cover representative attacks and editor behavior. They do not establish complete exploit resistance, accessibility compliance, or correctness in all browser engines. Report issues privately to the maintainer of the application using this library; no hosted reporting service or invented contact address is included. Avoid publishing exploit payloads containing real customer documents or credentials.

There aren't any published security advisories