Skip to content

fix(security): escape web search query output - #25

Merged
mstuart merged 1 commit into
mainfrom
fix/web-search-xss
Sep 24, 2026
Merged

mstuart merged 1 commit into
mainfrom
fix/web-search-xss

Conversation

@mstuart

@mstuart mstuart commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • escape untrusted web-search query text before rendering it in HTML
  • cover script/image payloads, entity-like input, encoded input, and benign Unicode text
  • preserve the current query parsing and public template API

Security impact

/search passed the raw HTTP request target value into both the <title> and <h1> HTML contexts. A raw request containing markup could therefore produce executable response HTML. The fix applies context-appropriate HTML text escaping at the shared rendering boundary.

Verification

  • git diff --check
  • cargo fmt --package code-memory -- --check
  • cargo test web::templates::tests
  • cargo test --test web_ui_test
  • cargo clippy -- -D warnings
  • cargo test
  • manual raw-request reproduction: the original script payload is now emitted as &lt;...&gt;

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T23:13:39.238950Z 21ee683 PR opened
🔒 Security Review ✅ Completed 2026-09-24T23:14:47.348275Z 21ee683 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mstuart
mstuart merged commit a45f828 into main Sep 24, 2026
3 checks passed
@mstuart
mstuart deleted the fix/web-search-xss branch September 24, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant