Skip to content

fix(server): sandbox user-provided SVGs - #5916

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/secure-svg-rendering
Aug 9, 2026
Merged

t3dotgg merged 1 commit into
mainfrom
t3code/secure-svg-rendering

fix(server): sandbox user-provided SVGs

457efa6
Select commit
Loading
Failed to load commit list.
MacroscopeApp / Macroscope - Approvability Check succeeded Aug 9, 2026 in 7m 42s

Approved (click on check for details)

  • Eligibility
  • Correctness

Note

More information about how approvability works can be found in our Help Center.

Details

Eligibility
This PR adds standard security hardening by sandboxing user-provided SVG files with restrictive CSP headers to prevent XSS attacks. The change is small, well-tested, and follows established security best practices for handling untrusted SVG content.

Notes:
No code owners found in target merge base 0d38866