Skip to content

#943: serialize QoS metrics as numeric values - #954

Open
gemshrine wants to merge 1 commit into
zerocracy:masterfrom
gemshrine:943
Open

gemshrine wants to merge 1 commit into
zerocracy:masterfrom
gemshrine:943

Conversation

@gemshrine

@gemshrine gemshrine commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

QoS metric values were inserted directly into an inline JavaScript array. A string-valued fact could close the array and execute script in the origin of the published page.

The renderer now accepts only values castable to xs:decimal and emits the parsed decimal value. Missing or nonnumeric values become null, so fact contents remain data.

Checks: the regression case in TestQoSection#test_non_numeric_metric_values_are_not_emitted_as_javascript and the repository's Ruby/XSLT CI suite.

Closes #943

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Quality-of-service metrics allow string injection in JavaScript chart rendering

1 participant