Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malicious JSON RPC request unit test #1884

Conversation

Stefan-Ethernal
Copy link
Collaborator

@Stefan-Ethernal Stefan-Ethernal commented Sep 7, 2023

Description

The original idea behind this PR was to resolve the following security findings
This PR aims to fix the following security checks that are related to cross-site scripting attack vector.

Idea was to escape HTML content from response using template.HTMLEscape, but it turns out that when doing so, that function fails internally.

So the behavior is reverted to the old one (response is written into the buffer directly) and unit tests which proves that we don't have an issue are added.

Mentioned security issues are going to be marked as not relevant.

Changes include

  • Bugfix (non-breaking change that solves an issue)
  • Hotfix (change that solves an urgent issue, and requires immediate attention)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (change that is not backwards-compatible and/or changes current functionality)

Checklist

  • I have assigned this PR to myself
  • I have added at least 1 reviewer
  • I have added the relevant labels
  • I have updated the official documentation
  • I have added sufficient documentation in code

Testing

  • I have tested this code with the official test suite
  • I have tested this code manually

@Stefan-Ethernal Stefan-Ethernal added the bug fix Functionality that fixes a bug label Sep 7, 2023
@Stefan-Ethernal Stefan-Ethernal self-assigned this Sep 7, 2023
@Stefan-Ethernal Stefan-Ethernal requested a review from a team September 7, 2023 07:52
@Stefan-Ethernal Stefan-Ethernal changed the title Sanitize JSON RPC response Malicious JSON RPC request unit test Sep 12, 2023
@Stefan-Ethernal Stefan-Ethernal merged commit 4a45018 into develop Sep 12, 2023
7 checks passed
@Stefan-Ethernal Stefan-Ethernal deleted the EVM-829-sanitize-json-rpc-response-in-order-to-prevent-cross-site-scripting branch September 12, 2023 07:46
@github-actions github-actions bot locked and limited conversation to collaborators Sep 12, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug fix Functionality that fixes a bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants