Sanitize actor displaynames (#4864)

* Sanitize AP name possible XSS

* Pull out sanitizing method + remove rendering markdown for AP chat messages

* Add tests around AP message rendering and usernames

* Add sanitization tests to AP integration test
This commit is contained in:
Gabe Kangas
2026-03-31 20:33:05 -07:00
committed by GitHub
parent a2981903c2
commit e738156fd7
7 changed files with 783 additions and 109 deletions
+13 -4
View File
@@ -4,12 +4,24 @@ import (
"fmt"
"github.com/go-fed/activity/streams/vocab"
"github.com/microcosm-cc/bluemonday"
"github.com/owncast/owncast/activitypub/resolvers"
"github.com/owncast/owncast/core/chat"
"github.com/owncast/owncast/core/chat/events"
"github.com/owncast/owncast/persistence/configrepository"
)
// sanitizeActorName strips HTML tags from the ActivityPub actor display name.
// Falls back to the username if the display name is empty or entirely HTML.
func sanitizeActorName(displayName, username string) string {
strict := bluemonday.StrictPolicy()
name := strict.Sanitize(displayName)
if name == "" {
name = strict.Sanitize(username)
}
return name
}
func handleEngagementActivity(eventType events.EventType, isLiveNotification bool, actorReference vocab.ActivityStreamsActorProperty, action string) error {
configRepository := configrepository.Get()
@@ -30,10 +42,7 @@ func handleEngagementActivity(eventType events.EventType, isLiveNotification boo
}
// Send chat message
actorName := actor.Name
if actorName == "" {
actorName = actor.Username
}
actorName := sanitizeActorName(actor.Name, actor.Username)
actorIRI := actor.ActorIriString()
userPrefix := fmt.Sprintf("%s ", actorName)