diff options
Diffstat (limited to 'internal/web/render_test.go')
| -rw-r--r-- | internal/web/render_test.go | 16 |
1 files changed, 11 insertions, 5 deletions
diff --git a/internal/web/render_test.go b/internal/web/render_test.go index c05a83c..39bcc58 100644 --- a/internal/web/render_test.go +++ b/internal/web/render_test.go @@ -80,13 +80,19 @@ func TestThemeCSSGuardRejectsInvalidNames(t *testing.T) { } func TestRenderReadingsEscapesScriptText(t *testing.T) { + // An attacker-controlled version code (?v=... reaches RenderReadings + // unfiltered) flows to render.GatherVersion as both the column label and the + // "(not in %s)" note. RenderReadings must HTML-escape it: it renders through + // html/template, never wrapping untrusted text in template.HTML. + const evil = "<script>alert(1)</script>" secs := []liturgy.Section{{ - Heading: "Test", - PartID: "pierwsze_czytanie", - Paragraphs: [][]string{{"<script>alert(1)</script>"}}, + Heading: "Ewangelia", + Citation: "J 20, 1. 11-18", + Ref: "John 20:1,11-18", + PartID: "pierwsze_czytanie", }} - html := string(RenderReadings(secs, []string{"bt"}, "new", "horizontal", "pl", liturgy.DayInfo{})) - if strings.Contains(html, "<script>alert(1)</script>") { + html := string(RenderReadings(secs, []string{evil}, "new", "horizontal", "pl", liturgy.DayInfo{})) + if strings.Contains(html, evil) { t.Errorf("raw <script> leaked into rendered output: %q", html) } if !strings.Contains(html, "<script>alert(1)</script>") { |
