# HG changeset patch # User Thomas De Schampheleire # Date 2019-01-26 20:00:14 # Node ID c9159e6fda042b0521d73f56abab551e40d0623d # Parent 42a150500c2531cd13c41daab179d2e4f6082fda cleanup: remove unnecessary (and potentially problematic) use of 'literal' webhelpers.html.literal (kallithea.lib.helpers.literal) is only needed when the passed string may contain HTML that needs to be interpreted literally. It is unnecessary for plain strings. Incorrect usage of literal can lead to XSS issues, via a malicious user controlling data which will be rendered in other users' browsers. The data could either be stored previously in the system or be part of a forged URL the victim clicks on. For example, when a user browses to a forged URL where a repository changeset or branch name contains a javascript snippet, the snippet was executed when printed on the page using 'literal'. Remaining uses of 'literal' have been reviewed with no apparent problems found. Reported by Bob Hogg (thanks!). diff --git a/kallithea/controllers/changelog.py b/kallithea/controllers/changelog.py --- a/kallithea/controllers/changelog.py +++ b/kallithea/controllers/changelog.py @@ -64,8 +64,7 @@ class ChangelogController(BaseRepoContro try: return c.db_repo_scm_instance.get_changeset(rev) except EmptyRepositoryError as e: - h.flash(h.literal(_('There are no changesets yet')), - category='error') + h.flash(_('There are no changesets yet'), category='error') except RepositoryError as e: log.error(traceback.format_exc()) h.flash(safe_str(e), category='error') diff --git a/kallithea/controllers/pullrequests.py b/kallithea/controllers/pullrequests.py --- a/kallithea/controllers/pullrequests.py +++ b/kallithea/controllers/pullrequests.py @@ -249,7 +249,7 @@ class PullrequestsController(BaseRepoCon try: org_scm_instance.get_changeset() except EmptyRepositoryError as e: - h.flash(h.literal(_('There are no changesets yet')), + h.flash(_('There are no changesets yet'), category='warning') raise HTTPFound(location=url('summary_home', repo_name=org_repo.repo_name)) diff --git a/kallithea/lib/auth.py b/kallithea/lib/auth.py --- a/kallithea/lib/auth.py +++ b/kallithea/lib/auth.py @@ -734,7 +734,7 @@ def _redirect_to_login(message=None): The optional message will be shown in a flash message.""" from kallithea.lib import helpers as h if message: - h.flash(h.literal(message), category='warning') + h.flash(message, category='warning') p = request.path_qs log.debug('Redirecting to login page, origin: %s', p) return HTTPFound(location=url('login_home', came_from=p)) diff --git a/kallithea/lib/base.py b/kallithea/lib/base.py --- a/kallithea/lib/base.py +++ b/kallithea/lib/base.py @@ -580,7 +580,7 @@ class BaseRepoController(BaseController) log.error('%s this repository is present in database but it ' 'cannot be created as an scm instance', c.repo_name) from kallithea.lib import helpers as h - h.flash(h.literal(_('Repository not found in the filesystem')), + h.flash(_('Repository not found in the filesystem'), category='error') raise webob.exc.HTTPNotFound() @@ -602,12 +602,11 @@ class BaseRepoController(BaseController) except EmptyRepositoryError as e: if returnempty: return repo.scm_instance.EMPTY_CHANGESET - h.flash(h.literal(_('There are no changesets yet')), - category='error') + h.flash(_('There are no changesets yet'), category='error') raise webob.exc.HTTPNotFound() except ChangesetDoesNotExistError as e: - h.flash(h.literal(_('Changeset for %s %s not found in %s') % - (ref_type, ref_name, repo.repo_name)), + h.flash(_('Changeset for %s %s not found in %s') % + (ref_type, ref_name, repo.repo_name), category='error') raise webob.exc.HTTPNotFound() except RepositoryError as e: diff --git a/kallithea/templates/admin/settings/settings_system_update.html b/kallithea/templates/admin/settings/settings_system_update.html --- a/kallithea/templates/admin/settings/settings_system_update.html +++ b/kallithea/templates/admin/settings/settings_system_update.html @@ -6,7 +6,7 @@ %if c.should_upgrade: A new version is available: %if c.latest_data.get('title'): - ${h.literal(c.latest_data['title'])} + ${c.latest_data['title']} %else: ${c.latest_ver} %endif diff --git a/kallithea/templates/base/default_perms_box.html b/kallithea/templates/base/default_perms_box.html --- a/kallithea/templates/base/default_perms_box.html +++ b/kallithea/templates/base/default_perms_box.html @@ -24,7 +24,7 @@ ${h.form(form_url)}
${h.checkbox('create_repo_perm',value=True)} - ${h.literal(_('Select this option to allow repository creation for this user'))} + ${_('Select this option to allow repository creation for this user')}
@@ -34,7 +34,7 @@ ${h.form(form_url)}
${h.checkbox('create_user_group_perm',value=True)} - ${h.literal(_('Select this option to allow user group creation for this user'))} + ${_('Select this option to allow user group creation for this user')}
@@ -44,7 +44,7 @@ ${h.form(form_url)}
${h.checkbox('fork_repo_perm',value=True)} - ${h.literal(_('Select this option to allow repository forking for this user'))} + ${_('Select this option to allow repository forking for this user')}