Sanitize actor displaynames (#4864)
* Sanitize AP name possible XSS * Pull out sanitizing method + remove rendering markdown for AP chat messages * Add tests around AP message rendering and usernames * Add sanitization tests to AP integration test
This commit is contained in:
@@ -4,12 +4,24 @@ import (
|
||||
"fmt"
|
||||
|
||||
"github.com/go-fed/activity/streams/vocab"
|
||||
"github.com/microcosm-cc/bluemonday"
|
||||
"github.com/owncast/owncast/activitypub/resolvers"
|
||||
"github.com/owncast/owncast/core/chat"
|
||||
"github.com/owncast/owncast/core/chat/events"
|
||||
"github.com/owncast/owncast/persistence/configrepository"
|
||||
)
|
||||
|
||||
// sanitizeActorName strips HTML tags from the ActivityPub actor display name.
|
||||
// Falls back to the username if the display name is empty or entirely HTML.
|
||||
func sanitizeActorName(displayName, username string) string {
|
||||
strict := bluemonday.StrictPolicy()
|
||||
name := strict.Sanitize(displayName)
|
||||
if name == "" {
|
||||
name = strict.Sanitize(username)
|
||||
}
|
||||
return name
|
||||
}
|
||||
|
||||
func handleEngagementActivity(eventType events.EventType, isLiveNotification bool, actorReference vocab.ActivityStreamsActorProperty, action string) error {
|
||||
configRepository := configrepository.Get()
|
||||
|
||||
@@ -30,10 +42,7 @@ func handleEngagementActivity(eventType events.EventType, isLiveNotification boo
|
||||
}
|
||||
|
||||
// Send chat message
|
||||
actorName := actor.Name
|
||||
if actorName == "" {
|
||||
actorName = actor.Username
|
||||
}
|
||||
actorName := sanitizeActorName(actor.Name, actor.Username)
|
||||
actorIRI := actor.ActorIriString()
|
||||
|
||||
userPrefix := fmt.Sprintf("%s ", actorName)
|
||||
|
||||
Reference in New Issue
Block a user