Files
ever-gauzy/sonar-project.properties
T
Ruslan KonviserandClaude Fable 5 4408ff7a0a fix(docs): close a ReDoS in the prompt neutralizer and stop bypassing sanitization
Static analysis on the pull request flagged two genuine security problems in
paths that handle untrusted content, plus a batch of accessibility defects.

- The neutralizer that fences document text before it reaches an AI prompt used
  a pattern vulnerable to exponential backtracking. Since it runs over uploaded
  content, a crafted document could pin a request thread. The pattern no longer
  backtracks, with a test that asserts a pathological input completes promptly
  and is still neutralized.
- Two render paths bypassed the framework sanitizer while displaying document
  content, which is attacker-controlled by definition: an uploaded HTML file or
  a page authored by someone else. Both now sanitize before rendering, covered
  by tests for script tags, event-handler attributes and javascript: URLs.
- Form controls across the filter bar, bulk bar, saved views, share dialog and
  the editor now carry associated labels.
- Reduced the complexity of the chunker, block splitter and upload service by
  extracting helpers. Behavior is unchanged: the chunker refactor was validated
  by a differential harness over ~9,900 comparisons, and the upload refactor by
  43 scenarios comparing both results and ordered side effects, each checked
  against deliberately broken variants to prove the harness detects breakage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 06:33:53 +02:00

76 lines
3.9 KiB
Properties

# =============================================================================
# SonarQube/SonarCloud Configuration for Ever Gauzy
# =============================================================================
# Project Identification
sonar.projectKey=ever-co_ever-gauzy
sonar.projectName=Ever Gauzy
sonar.projectVersion=0.1.0
sonar.sourceEncoding=UTF-8
# Organization (required for SonarCloud)
sonar.organization=ever-co
# =============================================================================
# Source Configuration
# =============================================================================
# Monorepo source directories (only existing top-level folders)
sonar.sources=apps,packages,.scripts,tools
# Test directories (same as sources - tests are co-located)
sonar.tests=apps,packages
# Test file patterns (TypeScript/JavaScript test files). `**/*.steps.ts` are the playwright-bdd step
# definitions — test code, classified like the specs they replaced (not main source).
sonar.test.inclusions=**/*.spec.ts,**/*.test.ts,**/*.spec.tsx,**/*.test.tsx,**/*.e2e-spec.ts,**/*.steps.ts
# =============================================================================
# Exclusions
# =============================================================================
# Exclude dependencies, build outputs, and generated files.
#
# `_katex.scss` is vendored, minified, third-party CSS: it is `katex@0.16.47`'s own
# `dist/katex.min.css` with only the font URLs rewritten, regenerated by
# `packages/plugins/docs-ui/tools/generate-katex-css.js` and marked "DO NOT EDIT BY HAND".
# Analyzing it reported 24 "missing generic font family" bugs plus a duplicate `.katex svg`
# selector — all upstream KaTeX's, none fixable here: hand-edits would be wiped by the next
# regeneration and would diverge this copy from upstream. It matches the spirit of the
# `**/*.min.css` exclusion already above and only misses it because of the `.scss` suffix.
sonar.exclusions=**/node_modules/**,**/dist/**,**/build/**,**/out/**,**/.angular/**,**/.nx/**,**/.cache/**,**/coverage/**,**/tmp/**,**/*.d.ts,**/*.min.js,**/*.min.css,**/assets/**,**/public/**,**/*.json,**/*.md,**/docs-ui/src/lib/editor/styles/_katex.scss
# Exclude test files from coverage analysis (they are analyzed as tests)
sonar.coverage.exclusions=**/*.spec.ts,**/*.test.ts,**/*.spec.tsx,**/*.test.tsx,**/*.e2e-spec.ts,**/test/**,**/tests/**,**/e2e/**,**/__mocks__/**,**/__tests__/**
# Exclude files from duplication detection. The whole gauzy-e2e project is test code, and the
# playwright-bdd step files (`**/*.steps.ts`) intentionally repeat similar page-object call sequences
# 1:1 from the specs they replaced — copy-paste detection there is noise (the old `*.spec.ts` were
# already excluded for the same reason).
sonar.cpd.exclusions=**/*.spec.ts,**/*.test.ts,**/*.steps.ts,apps/gauzy-e2e/**,**/migrations/**,**/fixtures/**,**/*.mock.ts
# =============================================================================
# Coverage Configuration
# =============================================================================
# LCOV coverage report paths (Jest generates these)
sonar.javascript.lcov.reportPaths=coverage/lcov.info,coverage/**/lcov.info,apps/**/coverage/lcov.info,packages/**/coverage/lcov.info
# =============================================================================
# TypeScript Configuration
# =============================================================================
# TypeScript configuration file for type resolution
sonar.typescript.tsconfigPath=tsconfig.base.json
# =============================================================================
# Language-specific Settings
# =============================================================================
# Set the main language to TypeScript
sonar.language=ts
# File suffixes for TypeScript and JavaScript analysis
sonar.typescript.file.suffixes=.ts,.tsx
sonar.javascript.file.suffixes=.js,.jsx,.mjs,.cjs