Repository navigation
Escape entry values in the meta tags - #58
Merged
Merged
Conversation
The meta view printed every value straight into element text or into a
content="..." attribute. Antlers does not escape output, so markup in an entry
title rendered as markup rather than text, and a double quote closed the
attribute early and turned the rest of the value into attributes on the meta
element.
Found on a storefront whose product titles come from supplier import files, so
the values are not authored by us. Setting one title to
Boilersuit </script><img src=x onerror=alert(1)> 12" & 'co'
put a working <img onerror> into the title element and both the og:title and
twitter:title tags.
All sixteen values are now escaped, not just the titles: description, robots,
canonical, the og set and the twitter set are all in the same position.
sanitize is htmlspecialchars with ENT_QUOTES and double_encode off, so it covers
the attribute case and is idempotent, and a value with no markup is unchanged
once the browser decodes it.
The values sit inside yield fallbacks, which render empty unless a section
supplies them, so the test asserts the shape of the template rather than its
output. It fails if any value is printed without escaping, including one added
later.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The meta view printed every value straight into element text or a
content="..."attribute. Antlers doesn't escape output, so markup in an entry title rendered as markup, and a double quote closed the attribute early — turning the rest of the value into attributes on the meta element.Found on a storefront whose product titles come from supplier import files, so the values aren't authored by us. Setting one title to
Boilersuit </script><img src=x onerror=alert(1)> 12" & 'co'put a working<img onerror>into the title element and both the og:title and twitter:title tags.All sixteen values are now escaped, not just the titles — description, robots, canonical, the og set and the twitter set are all in the same position.
sanitizeishtmlspecialcharswithENT_QUOTESanddouble_encodeoff, so it covers the attribute case, is idempotent, and leaves a plain value unchanged once decoded.The values sit inside yield fallbacks, which render empty unless a section supplies them, so the test asserts the shape of the template rather than its output: it fails if any value is printed without escaping, including one added later. 10 tests green.
Needs a release and a version bump on the sites afterwards — OSS is on ^1.4.
https://linear.app/alt-design/issue/DEV-6488/fix-entry-titles-are-not-escaped-in-the-meta-tags-so-markup-in-a-title