From 2955f414ddc29f725fd940febf19894255252875 Mon Sep 17 00:00:00 2001 From: Dan Brown Date: Tue, 6 Aug 2019 21:08:24 +0100 Subject: [PATCH] Added iframe JS and data url escaping Related to #1531 --- app/Entities/Repos/EntityRepo.php | 6 ++++++ tests/Entity/PageContentTest.php | 34 +++++++++++++++++++++++++++++++ 2 files changed, 40 insertions(+) diff --git a/app/Entities/Repos/EntityRepo.php b/app/Entities/Repos/EntityRepo.php index aad9a1205..7ca25b785 100644 --- a/app/Entities/Repos/EntityRepo.php +++ b/app/Entities/Repos/EntityRepo.php @@ -765,6 +765,12 @@ class EntityRepo $scriptElem->parentNode->removeChild($scriptElem); } + // Remove data or JavaScript iFrames + $badIframes = $xPath->query('//*[contains(@src, \'data:\')] | //*[contains(@src, \'javascript:\')]'); + foreach ($badIframes as $badIframe) { + $badIframe->parentNode->removeChild($badIframe); + } + // Remove 'on*' attributes $onAttributes = $xPath->query('//@*[starts-with(name(), \'on\')]'); foreach ($onAttributes as $attr) { diff --git a/tests/Entity/PageContentTest.php b/tests/Entity/PageContentTest.php index c80b5f1d9..b447a7c5d 100644 --- a/tests/Entity/PageContentTest.php +++ b/tests/Entity/PageContentTest.php @@ -80,6 +80,7 @@ class PageContentTest extends TestCase $page->save(); $pageView = $this->get($page->getUrl()); + $pageView->assertStatus(200); $pageView->assertDontSee($script); $pageView->assertSee('abc123abc123'); } @@ -103,12 +104,42 @@ class PageContentTest extends TestCase $page->save(); $pageView = $this->get($page->getUrl()); + $pageView->assertStatus(200); $pageView->assertElementNotContains('.page-content', ''); } } + public function test_iframe_js_and_base64_urls_are_removed() + { + $checks = [ + '', + '', + '', + '', + + ]; + + $this->asEditor(); + $page = Page::first(); + + foreach ($checks as $check) { + $page->html = $check; + $page->save(); + + $pageView = $this->get($page->getUrl()); + $pageView->assertStatus(200); + $pageView->assertElementNotContains('.page-content', ''); + $pageView->assertElementNotContains('.page-content', 'src='); + $pageView->assertElementNotContains('.page-content', 'javascript:'); + $pageView->assertElementNotContains('.page-content', 'data:'); + $pageView->assertElementNotContains('.page-content', 'base64'); + } + + } + public function test_page_inline_on_attributes_removed_by_default() { $this->asEditor(); @@ -118,6 +149,7 @@ class PageContentTest extends TestCase $page->save(); $pageView = $this->get($page->getUrl()); + $pageView->assertStatus(200); $pageView->assertDontSee($script); $pageView->assertSee('

Hello

'); } @@ -130,6 +162,7 @@ class PageContentTest extends TestCase '
Lorem ipsum dolor sit amet.

Hello

', '
Lorem ipsum dolor sit amet.

Hello

', '
Lorem ipsum dolor sit amet.

Hello

', + '