Skip to content

feat/CTORNDSD-489: security updates - #11

Merged
Zlodej43sm merged 7 commits into
developfrom
feature/CTORNDSD-489-security
Jul 22, 2026
Merged

Zlodej43sm merged 7 commits into
developfrom
feature/CTORNDSD-489-security

Conversation

@Zlodej43sm

Copy link
Copy Markdown
Collaborator

No description provided.

@Zlodej43sm
Zlodej43sm requested review from Copilot and rcasian July 21, 2026 06:51
@Zlodej43sm
Zlodej43sm changed the base branch from main to develop July 21, 2026 06:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds A2UI renderer hardening to reduce XSS/navigation injection risk and to bound resource usage when rendering LLM-produced A2UI specs, alongside minor security documentation tweaks.

Changes:

  • Introduces a dependency-free A2UI security module (resource limits, URL scheme validation, attribute sanitization) and documents/enforces it via system prompt updates.
  • Enforces URL sanitization across multiple A2UI renderers and adds spec resource-limit checks (with a safe fallback UI) to renderA2UISpec.
  • Adds targeted unit tests to validate the new security behavior at both the pure-function and renderer levels.

Reviewed changes

Copilot reviewed 21 out of 21 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
SECURITY.md Minor update to vulnerability reporting contact formatting.
libs/ui/src/utils/a2ui/types.ts Adds A2UISecurityOptions type for configuring renderer security behavior.
libs/ui/src/utils/a2ui/renderers/skeleton.tsx Sanitizes free-form attributes before spreading onto the component.
libs/ui/src/utils/a2ui/renderers/sidebar.tsx Validates sidebar item href values via isSafeA2UIUrl.
libs/ui/src/utils/a2ui/renderers/link.tsx Ensures link href is dropped when unsafe.
libs/ui/src/utils/a2ui/renderers/image.tsx Ensures image src values are dropped when unsafe.
libs/ui/src/utils/a2ui/renderers/header.tsx Validates header mobile menu path values via isSafeA2UIUrl.
libs/ui/src/utils/a2ui/renderers/content-carousel.tsx Validates legacy carousel image src before creating image nodes.
libs/ui/src/utils/a2ui/renderers/chat.tsx Validates chat image gallery src values via isSafeA2UIUrl.
libs/ui/src/utils/a2ui/renderers/card.tsx Validates card-image src before rendering.
libs/ui/src/utils/a2ui/renderers/avatar.tsx Validates avatar src before rendering.
libs/ui/src/utils/a2ui/render.tsx Adds resource-limit check and a safe fallback notification when limits are exceeded.
libs/ui/src/utils/a2ui/helpers/options.tsx Validates option-like item href values via isSafeA2UIUrl.
libs/ui/src/utils/a2ui/constants.ts Adds a test id for the security fallback UI.
libs/ui/src/utils/a2ui-security.test.tsx Adds renderer-level security tests (limits fallback, unsafe href, attribute injection).
libs/ui/src/ai/a2ui/system-prompt.ts Adds a “SECURITY RULES” section to steer LLM output away from unsafe constructs.
libs/ui/src/ai/a2ui/system-prompt.test.ts Asserts the system prompt includes enforced security rules and correct values.
libs/ui/src/ai/a2ui/security.ts New security primitives: limit checking, URL scheme validation, attribute sanitization.
libs/ui/src/ai/a2ui/security.test.ts Unit tests for the new security primitives.
libs/ui/src/ai/a2ui/index.ts Exports security utilities from the gd-design-library/ai subpath.
libs/ui/src/ai/a2ui/A2UI_PROTOCOL.md Documents the new security model and how ingest/render should enforce it.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread libs/ui/src/ai/a2ui/security.ts Outdated
Comment thread libs/ui/src/ai/a2ui/security.ts Outdated
Zlodej43sm and others added 4 commits July 21, 2026 09:02
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@Zlodej43sm
Zlodej43sm requested a review from tjeleascov July 21, 2026 12:47
@Zlodej43sm
Zlodej43sm merged commit 02408bc into develop Jul 22, 2026
4 checks passed
@Zlodej43sm
Zlodej43sm deleted the feature/CTORNDSD-489-security branch July 22, 2026 06:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants