Fixed command parsing to use raw_body and added default HTML escaping to outbound chat messages.
CI / Formatting (push) Successful in 4s
CI / Linting (push) Successful in 4s
CI / Tests (Python 3.12) (push) Successful in 21s
CI / Tests (Python 3.13) (push) Successful in 20s
CI / Tests (Python 3.14) (push) Successful in 17s
CI / Type Checking (push) Successful in 8s
CI / Spelling (push) Successful in 4s
Audit / Dependencies (push) Failing after 7s

I got bamboozled. The command system was originally built on the `body` field in Owncast's webhook payloads which contains rendered HTML rather than raw user input like I expected. Switching to `rawBody` makes more sense in my opinion, but doing so introduces a new risk: modules like custom commands can echo user input back to chat via placeholders like `$(1)` and, as it turns out, Owncast does not sanitize messages from integrations the way it does for regular users. This means unsanitized HTML could be injected into chat through the bot if the body was blindly swapped for the raw body.

All OwncastClient send methods now HTML-escape outgoing message bodies by default using markupsafe, with an `unsanitized=True` keyword-only opt-out for modules that intentionally need to send raw HTML.
This commit is contained in:
2026-03-26 19:42:49 -04:00
parent fa23ae982d
commit 2face83f65
7 changed files with 61 additions and 9 deletions
+1 -1
View File
@@ -421,7 +421,7 @@ class CommandDispatcher:
:param event: The chat event to check for commands.
"""
parsed = self._command_registry.parse(event.body)
parsed = self._command_registry.parse(event.raw_body)
if parsed is None:
return