Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion lerna.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@
"packages": [
"packages/*"
],
"version": "0.8.46",
"version": "0.8.47",
"npmClient": "yarn"
}
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "clarity",
"private": true,
"version": "0.8.46",
"version": "0.8.47",
"repository": "https://github.com/microsoft/clarity.git",
"author": "Sarvesh Nagpal <[email protected]>",
"license": "MIT",
Expand Down
4 changes: 2 additions & 2 deletions packages/clarity-decode/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "clarity-decode",
"version": "0.8.46",
"version": "0.8.47",
"description": "An analytics library that uses web page interactions to generate aggregated insights",
"author": "Microsoft Corp.",
"license": "MIT",
Expand All @@ -26,7 +26,7 @@
"url": "https://github.com/Microsoft/clarity/issues"
},
"dependencies": {
"clarity-js": "^0.8.46"
"clarity-js": "^0.8.47"
},
"devDependencies": {
"@rollup/plugin-commonjs": "^24.0.0",
Expand Down
8 changes: 4 additions & 4 deletions packages/clarity-devtools/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "clarity-devtools",
"version": "0.8.46",
"version": "0.8.47",
"private": true,
"description": "Adds Clarity debugging support to browser devtools",
"author": "Microsoft Corp.",
Expand All @@ -24,9 +24,9 @@
"url": "https://github.com/Microsoft/clarity/issues"
},
"dependencies": {
"clarity-decode": "^0.8.46",
"clarity-js": "^0.8.46",
"clarity-visualize": "^0.8.46"
"clarity-decode": "^0.8.47",
"clarity-js": "^0.8.47",
"clarity-visualize": "^0.8.47"
},
"devDependencies": {
"@rollup/plugin-node-resolve": "^15.0.0",
Expand Down
4 changes: 2 additions & 2 deletions packages/clarity-devtools/static/manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"manifest_version": 3,
"name": "Microsoft Clarity Developer Tools",
"description": "Clarity helps you understand how users are interacting with your website.",
"version": "0.8.46",
"version_name": "0.8.46",
"version": "0.8.47",
"version_name": "0.8.47",
"minimum_chrome_version": "88",
"devtools_page": "devtools.html",
"icons": {
Expand Down
2 changes: 1 addition & 1 deletion packages/clarity-js/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "clarity-js",
"version": "0.8.46",
"version": "0.8.47",
"description": "An analytics library that uses web page interactions to generate aggregated insights",
"author": "Microsoft Corp.",
"license": "MIT",
Expand Down
2 changes: 1 addition & 1 deletion packages/clarity-js/src/core/version.ts
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
let version = "0.8.46";
let version = "0.8.47";
export default version;
4 changes: 2 additions & 2 deletions packages/clarity-visualize/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "clarity-visualize",
"version": "0.8.46",
"version": "0.8.47",
"description": "An analytics library that uses web page interactions to generate aggregated insights",
"author": "Microsoft Corp.",
"license": "MIT",
Expand All @@ -27,7 +27,7 @@
"url": "https://github.com/Microsoft/clarity/issues"
},
"dependencies": {
"clarity-decode": "^0.8.46"
"clarity-decode": "^0.8.47"
},
"devDependencies": {
"@rollup/plugin-commonjs": "^24.0.0",
Expand Down
19 changes: 18 additions & 1 deletion packages/clarity-visualize/src/layout.ts
Original file line number Diff line number Diff line change
Expand Up @@ -641,7 +641,7 @@ export class LayoutHelper {
node.setAttribute(Constant.Hide, size);
}
} else {
node.setAttribute(attribute, v);
node.setAttribute(attribute, this.isSuspiciousAttribute(attribute, v) ? Constant.Empty : v);
}
} catch (ex) {
console.warn("Node: " + node + " | " + JSON.stringify(attributes));
Expand Down Expand Up @@ -670,6 +670,23 @@ export class LayoutHelper {
}
}

private isSuspiciousAttribute(name: string, value: string): boolean {
// Block event handlers entirely
if (name.startsWith('on')) {
return true;
}

// Check for JavaScript protocols and dangerous patterns
const dangerous = [
/^\s*javascript:/i,
/^\s*data:text\/html/i,
/^\s*vbscript:/i
];

return dangerous.some(pattern => pattern.test(value));
}


private getMobileCustomStyle = (): string => {
if(this.isMobile){
return `*{scrollbar-width: none; scrollbar-gutter: unset;};`
Expand Down
2 changes: 1 addition & 1 deletion packages/clarity-visualize/types/visualize.d.ts
Original file line number Diff line number Diff line change
Expand Up @@ -199,7 +199,7 @@ export const enum Constant {
NewPassword = "new-password",
StyleSheet = "stylesheet",
OriginalBackgroundColor = "data-clarity-background-color",
OriginalOpacity = "data-clarity-opacity"
OriginalOpacity = "data-clarity-opacity",
}

export const enum Setting {
Expand Down