--- name: security-guide description: Comprehensive security development guide for Mobazha decentralized marketplace covering XSS prevention, Web3 transaction safety, key management, and input validation. Use when working with user input, wallet operations, transactions, or security-sensitive features, "安全", "XSS", "注入", "钱包安全", "合约安全", "密钥管理". --- # 安全开发指南 Mobazha 去中心化市场的安全开发规范和最佳实践。 ## 项目安全现状 项目已有的安全基础设施: - `packages/core/utils/htmlUtils.ts` — DOMPurify HTML 清理 - `packages/core/services/api/wallet.ts` — 地址验证 API - `bignumber.js` — 精确金额计算 - ethers.js v6 — 地址规范化和签名 - 外部钱包 Provider — 私钥永不暴露给前端 ## 一、XSS 防护 ### 1.1 HTML 内容处理 **唯一允许的方式**:使用项目已有的 `sanitizeHtml()`: ```typescript import { sanitizeHtml, stripHtmlTags } from '@mobazha/core'; // 需要渲染 HTML 时(商品描述、店铺介绍)
// 只需要纯文本时 const plainText = stripHtmlTags(htmlContent); ``` **配置说明**(`htmlUtils.ts`): - 允许的标签:`h1-h6, p, a, img, ul, ol, li, blockquote, code, pre, br, hr, strong, em, span, div, table, tr, td, th` - 自动为 `` 添加 `target="_blank" rel="noopener noreferrer nofollow"` - 移除所有 `