Merge pull request 'fix: escape html notification variables' (#18) from feature/it-1115-html-template-escaping into main
Reviewed-on: #18
This commit was merged in pull request #18.
This commit is contained in:
+21
@@ -40,6 +40,27 @@ public sealed class EmailTemplateRenderingServiceTests
|
|||||||
Assert.Equal("Required template variables are missing: VerificationUrl.", exception.Message);
|
Assert.Equal("Required template variables are missing: VerificationUrl.", exception.Message);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void Render_HtmlEncodesVariablesWithoutChangingSubjectOrTextBody()
|
||||||
|
{
|
||||||
|
EmailTemplate template = CreateTemplate();
|
||||||
|
SendEmailMessageData data = CreateData(new Dictionary<string, string>
|
||||||
|
{
|
||||||
|
["AppName"] = "Invemory <script>alert('xss')</script>",
|
||||||
|
["VerificationUrl"] = "https://example.invalid/verify?next=\" onclick=\"alert('xss')"
|
||||||
|
});
|
||||||
|
|
||||||
|
RenderedEmail result = _service.Render(template, data);
|
||||||
|
|
||||||
|
Assert.Equal("Verify Invemory <script>alert('xss')</script>", result.Subject);
|
||||||
|
Assert.Equal(
|
||||||
|
"<a href=\"https://example.invalid/verify?next=" onclick="alert('xss')\">Verify</a>",
|
||||||
|
result.HtmlBody);
|
||||||
|
Assert.Equal(
|
||||||
|
"Verify at https://example.invalid/verify?next=\" onclick=\"alert('xss')",
|
||||||
|
result.TextBody);
|
||||||
|
}
|
||||||
|
|
||||||
private static EmailTemplate CreateTemplate() => new()
|
private static EmailTemplate CreateTemplate() => new()
|
||||||
{
|
{
|
||||||
ServiceName = "StoreMate-Prod",
|
ServiceName = "StoreMate-Prod",
|
||||||
|
|||||||
+16
-2
@@ -1,5 +1,6 @@
|
|||||||
namespace HrynCo.NotificationService.Worker.Services.EmailProcessing;
|
namespace HrynCo.NotificationService.Worker.Services.EmailProcessing;
|
||||||
|
|
||||||
|
using System.Net;
|
||||||
using System.Text;
|
using System.Text;
|
||||||
using HrynCo.NotificationService.Contracts.Messages;
|
using HrynCo.NotificationService.Contracts.Messages;
|
||||||
using HrynCo.NotificationService.DAL.Abstract.Templates;
|
using HrynCo.NotificationService.DAL.Abstract.Templates;
|
||||||
@@ -22,15 +23,28 @@ internal sealed class EmailTemplateRenderingService : IEmailTemplateRenderingSer
|
|||||||
|
|
||||||
return new RenderedEmail(
|
return new RenderedEmail(
|
||||||
Interpolate(template.Subject, data.Variables),
|
Interpolate(template.Subject, data.Variables),
|
||||||
Interpolate(template.HtmlBody, data.Variables),
|
InterpolateHtml(template.HtmlBody, data.Variables),
|
||||||
Interpolate(template.TextBody, data.Variables));
|
Interpolate(template.TextBody, data.Variables));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static string InterpolateHtml(string text, IReadOnlyDictionary<string, string> variables)
|
||||||
|
{
|
||||||
|
return Interpolate(text, variables, WebUtility.HtmlEncode);
|
||||||
|
}
|
||||||
|
|
||||||
private static string Interpolate(string text, IReadOnlyDictionary<string, string> variables)
|
private static string Interpolate(string text, IReadOnlyDictionary<string, string> variables)
|
||||||
|
{
|
||||||
|
return Interpolate(text, variables, static value => value);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string Interpolate(
|
||||||
|
string text,
|
||||||
|
IReadOnlyDictionary<string, string> variables,
|
||||||
|
Func<string, string> encodeValue)
|
||||||
{
|
{
|
||||||
var sb = new StringBuilder(text);
|
var sb = new StringBuilder(text);
|
||||||
foreach (var (key, value) in variables)
|
foreach (var (key, value) in variables)
|
||||||
sb.Replace($"{{{{{key}}}}}", value);
|
sb.Replace($"{{{{{key}}}}}", encodeValue(value));
|
||||||
return sb.ToString();
|
return sb.ToString();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -112,3 +112,7 @@ flowchart TD
|
|||||||
M -->|retries exhausted| N[Publish terminal failure result]
|
M -->|retries exhausted| N[Publish terminal failure result]
|
||||||
N --> O[Nack original delivery without requeue]
|
N --> O[Nack original delivery without requeue]
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Template variables are treated as plain text. The worker HTML-encodes every variable while
|
||||||
|
rendering `HtmlBody`; subject and plain-text body interpolation preserve the original value.
|
||||||
|
Templates must express markup in `body.html` instead of supplying HTML through variables.
|
||||||
|
|||||||
Reference in New Issue
Block a user