Prechádzať zdrojové kódy

Quick fix to "Script self-injection in edit box".

In the 'Edit...' box, the sourceContent (which was written by a user)
has its < replaced with &lt; . This issue does not propagate to the
public timeline nor to the recipients of the post.

Reference: https://codeberg.org/grunfink/snac2/issues/53
default 3 rokov pred
rodič
commit
5be2239467
1 zmenil súbory, kde vykonal 4 pridanie a 2 odobranie
  1. 4 2
      html.c

+ 4 - 2
html.c

@@ -668,9 +668,11 @@ xs_str *html_entry_controls(snac *snac, xs_str *os, const xs_dict *msg, const ch
 
     s = xs_str_cat(s, "</form>\n");
 
-    char *prev_src = xs_dict_get(msg, "sourceContent");
+    const char *prev_src1 = xs_dict_get(msg, "sourceContent");
+
+    if (!xs_is_null(prev_src1) && strcmp(actor, snac->actor) == 0) {
+        xs *prev_src = xs_replace(prev_src1, "<", "&lt;");
 
-    if (!xs_is_null(prev_src) && strcmp(actor, snac->actor) == 0) {
         /* post can be edited */
         xs *s1 = xs_fmt(
             "<p><details><summary>%s</summary>\n"