From 2e427a052072f9973690e554d0ced4c0e7352dd7 Mon Sep 17 00:00:00 2001 From: Dan Milne Date: Sat, 2 May 2026 23:57:22 +1000 Subject: [PATCH] Add SvgScrubber to strip XSS payloads from uploaded app icons MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Application#sanitize_svg_icon already runs a Loofah scrubber on every icon upload, but the scrubber class itself was never tracked. Land it along with tests covering the four shapes that matter: - ) + + cleaned = scrub(svg) + + refute_match(/