mirror of
https://github.com/thecyberlearn/quantum-ai.git
synced 2026-08-18 18:12:58 +00:00
SECURITY FIXES: - Fix XSS vulnerability: Replace innerHTML with secure DOM manipulation - Prevent information disclosure: Implement secure error handling with logging - Add comprehensive server-side input validation with length limits - Add missing @login_required decorator to main view - Secure AI prompt generation with input sanitization and content filtering - Add output validation for AI-generated content TECHNICAL CHANGES: - Replace dangerous innerHTML usage with secure createElement approach - Add input validation for description (10-5000 chars), platform, and language - Implement prompt injection protection and inappropriate content filtering - Add comprehensive logging for debugging without exposing sensitive data - Validate AI output for malicious patterns and content quality These fixes address: - CVE-like XSS vulnerability (CRITICAL) - Information disclosure through error messages (HIGH) - Input validation bypass (MEDIUM) - Missing authorization controls (MEDIUM) - Prompt injection risks (LOW) 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
9 lines
255 B
Python
9 lines
255 B
Python
from django.urls import path
|
|
from . import views
|
|
|
|
app_name = 'social_ads_generator'
|
|
|
|
urlpatterns = [
|
|
path('', views.social_ads_generator_detail, name='detail'),
|
|
path('status/<uuid:request_id>/', views.social_ads_generator_status, name='status'),
|
|
] |