T09 · Insecure Skill Coding Practices
- Location
canvas/index.html:145- Finding
Stored DOM Cross-Site Scripting in the Legacy Nutrition Dashboard
- Content
View full analysis
0) { const categories = { "Breakfast": [], "Lunch": [], "Dinner": [], "Snacks": [] }; latest.meals.forEach(meal => { const localTime = new Date(new Date(meal.timestamp).toLocaleString('en-US', { timeZone: 'Asia/Yerevan' })); const hour = localTime.getHours(); let category = "Snacks"; if (hour >= 6 && hour < 12) category = "Breakfast"; else if (hour >= 13 && hour < 15) category = "Lunch"; else if (hour >= 19) category = "Dinner"; categories[category].push(meal); }); Object.keys(categories).forEach(cat => { if (categories[cat].length > 0) { logContent.innerHTML += `${cat}
`; categories[cat].forEach(meal => { const time = new Date(meal.timestamp).toLocaleTimeString([], { hour: '2-digit', minute: '2-digit', timeZone: 'Asia/Yerevan' }); logContent.innerHTML += ``; }); } }); } ``` ### Technical Analysis Meal records are loaded from `nutrition/daily_macros.json`. The legacy dashboard interpolates `meal.food`, `meal.protein`, `meal.carbs`, and `meal.fat` directly ...[truncated 1717 chars]${time}${meal.food}${Math.round(meal.calories)} kcal | P: ${meal.protein}g | C: ${meal.carbs}g | F: ${meal.fat}g- Remediation
View remediation
