Escape template output #13

closed cmc opened this on 2026-09-11 02:07 UTC

Discussion

cmc 2026-09-11 02:07 UTC

app/util.go imports text/template. Nothing interpolated is escaped: the search query in static/html/search.htm and head.htm, and every DA username, title and description written by DeviationList, ParseComments, BuildUserPlate and ParseDescription. The CSP blocks scripts but not markup, inline styles, meta refresh or injected forms; any title containing < corrupts the page.

Fix: switch to html/template; wrap the pre-built HTML fragments in template.HTML; escape strings in the Go builders with html.EscapeString and attribute-escape URLs. Add tests that a query and a title containing "><b> render as text.

Land before other template work.

Roadmap item 2.1, size M. See ROADMAP.md.

closed by commit 35d16226b9 by cmc: Escape everything rendered from user or DeviantArt input

2026-09-11 15:13 UTC