xss-sanitize 0.3.7.1 → 0.3.7.2
raw patch · 4 files changed
+23/−5 lines, 4 filesdep ~textPVP: minor bump suggested
API additions: PVP suggests at least a minor version bump
Dependency ranges changed: text
API changes (from Hackage documentation)
+ Text.HTML.SanitizeXSS: clearTags :: [Tag Text] -> [Tag Text]
+ Text.HTML.SanitizeXSS: clearTagsCustom :: (Text -> Bool) -> [Tag Text] -> [Tag Text]
Files
- ChangeLog.md +4/−0
- src/Text/HTML/SanitizeXSS.hs +14/−3
- test/main.hs +3/−0
- xss-sanitize.cabal +2/−2
ChangeLog.md view
@@ -1,3 +1,7 @@+# 0.3.7.2++Stops Tag Soup from escaping &"<> which breaks HTML entities+ # 0.3.7.1 add max height and max width as valid style attributes
src/Text/HTML/SanitizeXSS.hs view
@@ -13,6 +13,8 @@ , filterTags , safeTags , safeTagsCustom+ , clearTags+ , clearTagsCustom , balanceTags -- * Utilities@@ -57,11 +59,12 @@ -- | Parse the given text to a list of tags, apply the given filtering -- function, and render back to HTML. You can insert your own custom -- filtering, but make sure you compose your filtering function with--- 'safeTags' or 'safeTagsCustom'.+-- 'safeTags' and 'clearTags' or 'safeTagsCustom' and 'clearTagsCustom'. filterTags :: ([Tag Text] -> [Tag Text]) -> Text -> Text filterTags f = renderTagsOptions renderOptions {- optMinimize = \x -> x `member` voidElems -- <img><img> converts to <img />, <a/> converts to <a></a>- } . f . canonicalizeTags . parseTags+ optEscape = id -- stops &"<> from being escaped which breaks existing HTML entities+ , optMinimize = \x -> x `member` voidElems -- <img><img> converts to <img />, <a/> converts to <a></a>+ } . f . canonicalizeTags . parseTagsOptions (parseOptionsEntities (const Nothing)) voidElems :: Set T.Text voidElems = fromAscList $ T.words $ T.pack "area base br col command embed hr img input keygen link meta param source track wbr"@@ -108,9 +111,17 @@ | otherwise = safeTagsCustom safeName sanitizeAttr tags safeTagsCustom n a (t:tags) = t : safeTagsCustom n a tags +-- | Directly removes tags even if they are not closed properly.+-- This is importent to clear out both the script and iframe tag +-- in sequences like "<script><iframe></iframe>". clearTags :: [Tag Text] -> [Tag Text] clearTags = clearTagsCustom clearableTagName +-- | Directly removes tags, like clearTags, but uses a custom+-- function for determining which tags are safe.+--+-- @clearTagsCustom clearableTagName@ is equivalent to+-- 'clearTags'. clearTagsCustom :: (Text -> Bool) -> [Tag Text] -> [Tag Text] clearTagsCustom _ [] = [] clearTagsCustom clearableName (tag@(TagOpen name _) : tags)
test/main.hs view
@@ -27,6 +27,9 @@ main :: IO () main = hspec $ do+ describe "Sanitized HTML is not changed" $ do+ it "HTML entities should not be escaped" $ do+ test (filterTags safeTags) "text more text" "text more text" describe "html sanitizing" $ do it "big test" $ do let testHTML = " <a href='http://safe.com'>safe</a><a href='unsafe://hack.com'>anchor</a> <img src='evil://evil.com' /> <unsafe></foo> <bar /> <br></br> <b>Unbalanced</div><img src='http://safe.com'>"
xss-sanitize.cabal view
@@ -1,11 +1,11 @@ cabal-version: 1.12 --- This file has been generated from package.yaml by hpack version 0.35.0.+-- This file has been generated from package.yaml by hpack version 0.35.1. -- -- see: https://github.com/sol/hpack name: xss-sanitize-version: 0.3.7.1+version: 0.3.7.2 synopsis: sanitize untrusted HTML to prevent XSS attacks description: run untrusted HTML through Text.HTML.SanitizeXSS.sanitizeXSS to prevent XSS attacks. see README.md <http://github.com/yesodweb/haskell-xss-sanitize> for more details category: Web