Skip to content

Escape entry values in the meta tags - #58

Merged
Alt-Ben merged 1 commit into
mainfrom
dev-6488-escape-meta-values
Sep 3, 2026
Merged

Alt-Ben merged 1 commit into
mainfrom
dev-6488-escape-meta-values

Conversation

@Alt-Ben

@Alt-Ben Alt-Ben commented Sep 3, 2026

Copy link
Copy Markdown
Member

The meta view printed every value straight into element text or a content="..." attribute. Antlers doesn't escape output, so markup in an entry title rendered as markup, and a double quote closed the attribute early — turning the rest of the value into attributes on the meta element.

Found on a storefront whose product titles come from supplier import files, so the values aren't authored by us. Setting one title to Boilersuit </script><img src=x onerror=alert(1)> 12" & 'co' put a working <img onerror> into the title element and both the og:title and twitter:title tags.

All sixteen values are now escaped, not just the titles — description, robots, canonical, the og set and the twitter set are all in the same position.

sanitize is htmlspecialchars with ENT_QUOTES and double_encode off, so it covers the attribute case, is idempotent, and leaves a plain value unchanged once decoded.

The values sit inside yield fallbacks, which render empty unless a section supplies them, so the test asserts the shape of the template rather than its output: it fails if any value is printed without escaping, including one added later. 10 tests green.

Needs a release and a version bump on the sites afterwards — OSS is on ^1.4.

https://linear.app/alt-design/issue/DEV-6488/fix-entry-titles-are-not-escaped-in-the-meta-tags-so-markup-in-a-title

The meta view printed every value straight into element text or into a
content="..." attribute. Antlers does not escape output, so markup in an entry
title rendered as markup rather than text, and a double quote closed the
attribute early and turned the rest of the value into attributes on the meta
element.

Found on a storefront whose product titles come from supplier import files, so
the values are not authored by us. Setting one title to

    Boilersuit </script><img src=x onerror=alert(1)> 12" & 'co'

put a working <img onerror> into the title element and both the og:title and
twitter:title tags.

All sixteen values are now escaped, not just the titles: description, robots,
canonical, the og set and the twitter set are all in the same position.

sanitize is htmlspecialchars with ENT_QUOTES and double_encode off, so it covers
the attribute case and is idempotent, and a value with no markup is unchanged
once the browser decodes it.

The values sit inside yield fallbacks, which render empty unless a section
supplies them, so the test asserts the shape of the template rather than its
output. It fails if any value is printed without escaping, including one added
later.
@Alt-Ben
Alt-Ben merged commit 099dc7c into main Sep 3, 2026
2 checks passed
@Alt-Ben
Alt-Ben deleted the dev-6488-escape-meta-values branch September 3, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant