Files
homepage.veen.world/app/eslint.config.js
Kevin Veen-Birkenbach 7353e8d96a fix(iframe): hand the sinks the validated URL, not the parameter
The scheme and origin checks lived in a boolean guard in another function, so the raw query parameter still reached the iframe src, the history entry and window.open. The validator now returns the normalised href or null, and every sink consumes only that. Which URLs are accepted does not change: openIframe still checks the scheme alone, because the modal opens configured targets that are not among the page's iframe links.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 02:10:05 +02:00

80 lines
2.3 KiB
JavaScript

'use strict';
/**
* Correctness only — eslint's recommended set, no stylistic rules.
*
* The browser scripts are plain <script> tags sharing one global scope: each
* file declares some functions and calls others declared elsewhere. That is why
* they are listed as globals and why no-redeclare is off — the declaring file
* would otherwise be reported for defining its own function.
*/
const js = require('@eslint/js');
const globals = require('globals');
// Vendored libraries plus the functions static/js files call across each other.
// Keep this to names that really cross a file boundary. Every superfluous
// entry is a permanent no-undef blind spot for a typo of that name.
const SHARED = {
bootstrap: 'readonly',
marked: 'readonly',
$: 'readonly',
jQuery: 'readonly',
openDynamicPopup: 'readonly',
closeAllModals: 'readonly',
isSafeUrl: 'readonly',
safeUrl: 'readonly',
openIframe: 'readonly',
enterFullscreen: 'readonly',
exitFullscreen: 'readonly',
setFullWidth: 'readonly',
initFullWidthFromUrl: 'readonly',
adjustScrollContainerHeight: 'readonly',
updateCustomScrollbar: 'readonly',
};
module.exports = [
{ ignores: ['node_modules/**', 'static/vendor/**', 'cypress/screenshots/**'] },
{
files: ['static/js/**/*.js'],
languageOptions: {
ecmaVersion: 2022,
sourceType: 'script',
globals: { ...globals.browser, ...SHARED },
},
rules: {
...js.configs.recommended.rules,
'no-redeclare': 'off',
// vars: 'local' — a top-level function here is the API other files and
// the templates call, so only unused locals are a defect.
'no-unused-vars': [
'error',
{ vars: 'local', args: 'none', caughtErrors: 'none' },
],
},
},
{
files: ['cypress/**/*.js'],
languageOptions: {
ecmaVersion: 2022,
sourceType: 'script',
globals: {
...globals.browser,
...globals.mocha,
cy: 'readonly',
Cypress: 'readonly',
expect: 'readonly',
assert: 'readonly',
},
},
rules: js.configs.recommended.rules,
},
{
files: ['scripts/**/*.js', 'cypress.config.js', 'eslint.config.js'],
languageOptions: {
ecmaVersion: 2022,
sourceType: 'commonjs',
globals: globals.node,
},
rules: js.configs.recommended.rules,
},
];