fix(server): sandbox user-provided SVGs - #5916
Merged
Merged
MacroscopeApp / Macroscope - Approvability Check
succeeded
Aug 9, 2026 in 7m 42s
Approved (click on check for details)
- Eligibility
- Correctness
Note
More information about how approvability works can be found in our Help Center.
Details
Eligibility
This PR adds standard security hardening by sandboxing user-provided SVG files with restrictive CSP headers to prevent XSS attacks. The change is small, well-tested, and follows established security best practices for handling untrusted SVG content.
Notes:
No code owners found in target merge base 0d38866
Loading