Project

General

Profile

Actions

Feature #44585

open

Sanitize the HTML generated by the Textile formatter in the same way as the CommonMark formatter

Added by Go MAEDA about 13 hours ago. Updated about 9 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Text formatting
Target version:
Resolution:

Description

The CommonMark formatter passes the rendered HTML through an allowlist-based sanitizer (Redmine::WikiFormatting::CommonMark::SanitizationFilter). The Textile formatter has no such step and relies solely on the regular-expression-based escaping in RedCloth3 to produce safe HTML.

I would like to propose that the Textile formatter sanitize its output in the same way. This adds a second layer of protection to Textile and makes the two formatters consistent. To confirm the benefit, I temporarily reverted the fixes for #44047, #44138 and #44308 and found that the sanitizer alone blocks all three attacks.

The attached patches make the following changes:

  • 0001: Extracts the rules common to both formatters from CommonMark::SanitizationFilter into a base class, Redmine::WikiFormatting::SanitizationFilter. The behavior of the CommonMark formatter does not change.
  • 0002: Adds Textile::SanitizationFilter and applies it in Textile::Formatter#to_html. It inherits from the base class and only defines what is specific to Textile, such as the classes and ids generated by RedCloth3.
  • 0003: Allows the same CSS properties in the style attribute in both formatters. Until now, CommonMark accepted about 40 properties, while Textile accepts any property that matches RedCloth3::STYLES_RE. For example, background and vertical-align were accepted in Textile but removed in CommonMark.

With the default settings, the only visible change in Textile is that a double quote in a URL is rendered as %22 instead of ", because Sanitize percent-encodes it.

Rendering Textile takes roughly twice as long with the sanitizer. However, in my measurements it is still as fast as, or slightly faster than, rendering equivalent content with the CommonMark formatter.


Files


Related issues

Blocks Redmine - Defect #44586: Quoted attribute values are broken in HTML tags added to RedCloth3::ALLOWED_TAGSNewActions
Actions #1

Updated by Go MAEDA about 13 hours ago

  • Blocks Defect #44586: Quoted attribute values are broken in HTML tags added to RedCloth3::ALLOWED_TAGS added
Actions #2

Updated by Marius BĂLTEANU about 12 hours ago

  • Target version changed from Candidate for next major release to 7.1.0
Actions #3

Updated by Marius BĂLTEANU about 12 hours ago

Nice!

Actions #4

Updated by Go MAEDA about 9 hours ago

  • Tracker changed from Defect to Feature
Actions

Also available in: Atom PDF