Repository navigation
Conversation
Automated security fix generated by OrbisAI Security
|
@anupamme Thanks for the PR! I have a question: I couldn’t find any code path that renders the event title in the DOM. Would it make more sense to remove the title from the internal event object, since it doesn’t seem to be needed, rather than escaping it on input? If I’ve missed a place/an option where it is rendered, could you point me to the specific DOM sink? |
… guarantee event.title is never inserted into the DOM anywhere in this module (getDom/drawSlot only write innerHTML from Date/config-derived strings via formatPattern, never from event data), so escaping it at ingestion time fixed nothing live and corrupted the stored title (e.g. "&" became "&"). Revert the escapeHtml() call, keep the title field (still required by the pre-existing name/title/date filter), and add a test that proves no DOM sink exists today and will fail if one is ever added unsafely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Thanks for pushing on this — you're right, I couldn't find a sink either after re-checking. The only So I've updated the PR: kept the PR description updated with the full writeup. Appreciate you catching this. |
|
Thanks for working on this. It prompted me to clean up the code and remove the unused event-title handling. I’m closing this PR because the proposed change is no longer needed. |
Original finding
The automated scan flagged
updateContentFromCalendarEventsfor storingevent.titlefrom untrusted calendar sources (Google Calendar, CalDAV, ICS feeds) without sanitization, and the original version of this PR escapedevent.titleat ingestion time with a newescapeHtml()helper.A maintainer asked a fair question in review: is there actually a code path that renders the event title into the DOM? If not, escaping on input isn't the right fix, and it might make more sense to drop the field instead.
Investigation
MMM-CalendarExtMiniMonth.jsis the only JS source file in this module.getDom()anddrawSlot()are the only places that build DOM nodes, and the only threeinnerHTMLwrites are:header.innerHTML = formatPattern(new Date(), this.config.titleFormat, locale)(month header)cell.innerHTML = formatPattern(d, this.config.weekdayFormat, locale)(weekday initials)cell.innerHTML = formatPattern(date, this.config.dateFormat, locale)(day numbers)All three are driven by
Dateobjects plus a small fixedconfigenum ('MMMM','D','Do','dd', …) viaformatPattern()— never byevent.title.event.titleitself is used in exactly one other place: the pre-existing required-field filter (event.name && event.title && Number.isFinite(event.startDate) && Number.isFinite(event.endDate)), which just drops events missing a title. That filter predates this PR.Conclusion: there is no reachable DOM sink for
event.titlein this module today. Escaping it at ingestion was solving a problem that doesn't currently exist, was applied inconsistently (theCALEXT2ingestion path never went throughescapeHtmleither), and actively corrupted the stored data for a value that's never displayed (e.g.Research & DevelopmentbecameResearch & Developmentin memory).Updated fix
escapeHtml()helper and its call site —titleis stored raw again, exactly as onmain.titlefield on the internal event object, since it's still required by the pre-existing filter rule above; removing it would change unrelated filtering behavior.test/event-title-no-dom-sink.test.js(Node's built-innode:test, no new dependencies) that feeds normal and malicious titles (<script>alert(1)</script>,<img src=x onerror=alert(1)>,Research & Development,Tom's "Meeting", empty/missing) throughupdateContentFromCalendarEvents()+getDom(), and asserts: (a) titles are stored verbatim, and (b) they never appear in the serialized rendered DOM output. Verified this test actually fails if a title-rendering sink is reintroduced (temporarily added+ slot.events[0].titleto acell.innerHTMLassignment, confirmed the test caught it, then reverted).npm test(node --run lint && node --test), which CI already runs.Verification
npm testpasses locally (lint + 6 new test cases).mainforMMM-CalendarExtMiniMonth.jsnow only adds a comment; thetitle: event.title,line is byte-for-byte what's onmain.Automated security fix by OrbisAI Security