templates: escape query value in ping page
elem-go does not escape attribute values, so the raw query reaches the rendered HTML verbatim. Pre-escape with html.EscapeString to prevent reflected XSS. Updates #3157
This commit is contained in:
parent
3a4af8cf87
commit
f3eb9a7bba
3 changed files with 28 additions and 2 deletions
26
hscontrol/templates/ping_test.go
Normal file
26
hscontrol/templates/ping_test.go
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
package templates
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// TestPingPageEscapesQuery asserts hostile query values cannot break out of
|
||||
// the input's value attribute. elem-go does not escape attribute values, so
|
||||
// the template must escape before rendering.
|
||||
func TestPingPageEscapesQuery(t *testing.T) {
|
||||
payloads := []string{
|
||||
`" autofocus onfocus=alert(1) x="`,
|
||||
`"><script>alert(1)</script>`,
|
||||
`<img src=x onerror=alert(1)>`,
|
||||
}
|
||||
|
||||
for _, p := range payloads {
|
||||
t.Run(p, func(t *testing.T) {
|
||||
out := PingPage(p, nil, nil).Render()
|
||||
if strings.Contains(out, p) {
|
||||
t.Fatalf("unescaped payload rendered verbatim: %q", p)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue