Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/deploy-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ jobs:
env:
DOCS_BASE: ${{ steps.pages.outputs.base_path }}
DOCS_EDIT_BRANCH: ${{ github.ref_name }}
MEMPALACE_DOCS_GA_ID: ${{ vars.MEMPALACE_DOCS_GA_ID }}
run: bun run docs:build

- uses: actions/upload-pages-artifact@v5
Expand Down
4 changes: 2 additions & 2 deletions website/.vitepress/config.mts
Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,8 @@ export default withMermaid(
['meta', { property: 'og:description', content: '96.6% LongMemEval recall. Zero API calls. Local, free, open source.' }],
['meta', { property: 'og:image', content: `${docsBase}mempalace_logo.png` }],
...(gaId ? [
['script', { async: '', src: `https://www.googletagmanager.com/gtag/js?id=${gaId}` }],
['script', {}, `window.dataLayer = window.dataLayer || [];\nfunction gtag(){dataLayer.push(arguments);}\ngtag('js', new Date());\ngtag('config', '${gaId}');`],
['script', { async: '', src: `https://www.googletagmanager.com/gtag/js?id=${encodeURIComponent(gaId)}` }],
['script', {}, `window.dataLayer = window.dataLayer || [];\nfunction gtag(){dataLayer.push(arguments);}\ngtag('js', new Date());\ngtag('config', ${JSON.stringify(gaId)});`],
Comment on lines +33 to +34

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The pull request description mentions passing MEMPALACE_DOCS_GA_ID from the deploy workflow, but the necessary changes to the GitHub Actions workflow files (typically located in .github/workflows/) are not included in this PR. \n\nIn GitHub Actions, repository variables are not automatically injected into the environment of run steps. To ensure the analytics ID is available during the VitePress build, you must explicitly map it in your workflow file:\n\nyaml\n- name: Build Docs\n run: npm run docs:build\n env:\n MEMPALACE_DOCS_GA_ID: ${{ vars.MEMPALACE_DOCS_GA_ID }}\n\n\nWithout this, gaId will remain undefined in the production build, and the Google Analytics tags will not be rendered.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

While using JSON.stringify is a good improvement for handling quotes and special characters, it does not escape the HTML closing script tag </script>. If the environment variable were to contain this sequence, it could prematurely terminate the script block and lead to a Cross-Site Scripting (XSS) vulnerability. To fully harden the snippet as intended in the PR description, consider escaping the < character.

        ['script', {}, `window.dataLayer = window.dataLayer || [];\nfunction gtag(){dataLayer.push(arguments);}\ngtag('js', new Date());\ngtag('config', ${JSON.stringify(gaId).replace(/</g, '\\u003c')});`],

Comment on lines 32 to +34
] as const : []),
],

Expand Down
Loading