escape alarm expressions to avoid them being detected as xss
Costa Tsaousis (ktsaou) committed
Jan 29, 2018 at 22:55 UTC
6be273f30f338ffaa63bd4b2340c63d3bff8baea
3 files changed
+10
-7
src/health_json.c
+6
-2
@@ -2,8 +2,12 @@
2
#include "common.h"
3
4
static inline void health_string2json(BUFFER *wb, const char *prefix, const char *label, const char *value, const char *suffix) {
5
- if(value && *value)
6
- buffer_sprintf(wb, "%s\"%s\":\"%s\"%s", prefix, label, value, suffix);
5
+ if(value && *value) {
6
+ buffer_sprintf(wb, "%s\"%s\":\"", prefix, label);
7
+ buffer_strcat_htmlescape(wb, value);
8
+ buffer_strcat(wb, "\"");
9
+ buffer_strcat(wb, suffix);
10
+ }
11
else
12
buffer_sprintf(wb, "%s\"%s\":null%s", prefix, label, suffix);
13
}
src/web_buffer.c
+4
-4
@@ -160,8 +160,6 @@ void buffer_strcat(BUFFER *wb, const char *txt)
160
161
void buffer_strcat_htmlescape(BUFFER *wb, const char *txt)
162
{
163
- char b[2] = { [0] = '\0', [1] = '\0' };
164
-
163
while(*txt) {
164
switch(*txt) {
165
case '&': buffer_strcat(wb, "&"); break;
@@ -171,12 +169,14 @@ void buffer_strcat_htmlescape(BUFFER *wb, const char *txt)
169
case '/': buffer_strcat(wb, "/"); break;
170
case '\'': buffer_strcat(wb, "'"); break;
171
default: {
174
- b[0] = *txt;
175
- buffer_strcat(wb, b);
172
+ buffer_need_bytes(wb, 1);
173
+ wb->buffer[wb->len++] = *txt;
174
}
175
}
176
txt++;
177
}
178
+
179
+ buffer_overflow_check(wb);
180
}
181
182
void buffer_snprintf(BUFFER *wb, size_t len, const char *fmt, ...)
web/dashboard.js
-1
@@ -111,7 +111,6 @@ var NETDATA = window.NETDATA || {};
111
string: function (s) {
112
if (typeof s === 'string' || typeof s === 'number' || typeof s === 'boolean')
113
return s.toString()
114
- .replace(/&/g, '&')
114
.replace(/</g, '<')
115
.replace(/>/g, '>')
116
.replace(/"/g, '"')