You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is a follow-up to the SEO work from PR #604. It closes out the 3 items that were left over: a missing site-address setting, headings that were confusing search engines, and images with meaningless descriptions.
Nice work Raineer — this covers all three gaps from the follow-up: metadataBase is set, the JSON-LD is factored into one shared component instead of being copy-pasted per page, and the alt-text fixes are clean. Sorry for the slow review on my end.
One blocker before I can merge.
🔴 Stored XSS in JsonLd.tsx
app/(marketing)/_components/JsonLd.tsx:7-9:
// JSON.stringify is safe here — schema.org data is server-generated,// not raw user input, so no XSS risk via this dangerouslySetInnerHTML.dangerouslySetInnerHTML={{__html: JSON.stringify(data)}}
The comment isn't right — the data is user input on the profile pages. profiles/[id]/page.tsx:78-83 passes straight through:
Every one of those is self-editable in account settings. JSON.stringify escapes quotes but not <, so an About field containing </script><script>alert(1)</script> breaks out of the script tag and executes — on a public page that doesn't need a login. Same exposure through careers/_components/JobListings.tsx:171 and services/page.tsx:123. Only the two schemas in layout.tsx are safe, since those are hardcoded.
< is valid JSON and parses back to <, so the schema still validates in Google's Rich Results tool. Please drop the "no XSS risk" comment too so nobody relies on it later.
🟡 My spec pointed you at a dead file
This one's on me. I named LandingWhyChoose.tsx in the spec, but that file isn't imported anywhere — the homepage actually renders LandingWhyChoose-us.tsx. Your change is correct, it just doesn't affect anything live. The homepage still has 2 h1s, from AnimatedAdminsSection.tsx:20 and LandingInternSection.tsx:12.
Don't fix that here — I've written it up as a separate heading-cleanup task and I'll send it over.
🟢 Not yours, just noting it
/og-image.jpg doesn't exist in public/, and neither do the favicons declared in layout.tsx:46-50. Ironically your metadataBase fix is what made these resolve properly — straight to a 404, so link previews stay blank. That needs design to produce the assets, so I'm tracking it separately.
Once the escaping fix is in I'm happy to re-review and merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is a follow-up to the SEO work from PR #604. It closes out the 3 items that were left over: a missing site-address setting, headings that were confusing search engines, and images with meaningless descriptions.