Side B fixes a real XSS vulnerability by sanitizing untrusted Reddit HTML at render time with a well-scoped ammonia integration and includes targeted unit tests proving script/onerror stripping while preserving benign markup. Side A fixes a plausible bug in child-import path wiring and threads tree context for unranked labels, which is useful but more narrow and lower severity than closing a script-injection hole in rendered untrusted content.
constitution · epochs · watch · epoch 3
c_cd965c070df3 (tommy-mor) vs c_c0df72aee6da (tommy-mor)
download prompt · raw event · cmp_6180982466262e
council reasoning
B closes a lasting XSS hole by sanitizing untrusted Reddit body HTML with ammonia at render time (focused sanitize module + unit tests) instead of raw PreEscaped. A is a real functional fix (apply_entity_under_parent, title-based unranked labels, stronger import tests) but is feature/correctness work, not foundational safety like B.
Side B fixes a significant security issue by introducing HTML sanitization with the `ammonia` library and routing all Reddit `body_html` rendering through `entity_body_html`, preventing untrusted `selftext_html` from executing scripts while preserving benign markup with tests. Side A improves Reddit child import behavior by attaching imported posts directly under the subreddit and displaying child titles correctly, plus expands integration tests, but those are primarily functional correctness and UX improvements rather than a cross-cutting security hardening.
sides
A — c_cd965c070df3 (tommy-mor)
message
[993d359c] Fix Reddit children import wiring and unranked child labels. Listing imports attach posts directly under the subreddit without ensure_path pulling comment-path segments in, and the ranking panel shows imported titles. Update integration tests for JS SSE morphs and children fetch. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index d1defd28242fd2ca3b886adc91a7070bef75e653..e649a7d192feade465e19ce6187a829f6ec74372 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -58,7 +58,7 @@ pub async fn post_ui_html(
let tree = state.tree.read().await;
let empty = crate::reducer::NodeState::default();
let node = tree.get(&parent).unwrap_or(&empty);
- let panel = ranking_panel(&parent, node);
+ let panel = ranking_panel(&parent, node, &tree);
JsBuilder::new()
.morph_selector("#ranking-panel", panel)
.into_response()
diff --git a/server/src/fetch/mod.rs b/server/src/fetch/mod.rs
index 0177bb161cea1b72a100b52efdfc5e710271c9eb..35f968c21c69ca557bab7951413e3cfbbccfebfd 100644
--- a/server/src/fetch/mod.rs
+++ b/server/src/fetch/mod.rs
@@ -107,7 +107,7 @@ pub fn fetch_entity_stream(
let mut b = JsBuilder::new()
.morph_selector("#entity-section", html::entity_section(&id, node, false));
if kind == FetchKind::Children {
- b = b.morph_selector("#ranking-panel", ranking_panel(&id, node));
+ b = b.morph_selector("#ranking-panel", ranking_panel(&id, node, &tree));
}
yield Ok(js_event(b.build()));
}
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 27ce9118c73ec5643e04363ab1a36cf5da6101bf..e88cc43ddc9d8100f7994be6f5960ec4d8f22c55 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -15,7 +15,7 @@ use crate::{
ranking::{
connected_components_from_voted_pairs, ranked_items_subset, RankedItem, MAX_ITERS, TOL,
},
- reducer::NodeState,
+ reducer::{GlobalTree, NodeState},
state::AppState,
ui_action::UI_RPC_FIELD,
};
@@ -182,8 +182,15 @@ fn display_label(id: &ItemId) -> String {
.to_string()
}
+fn child_label(tree: &GlobalTree, id: &ItemId) -> String {
+ tree.get(id)
+ .and_then(|n| n.data.as_ref())
+ .map(|d| d.title.clone())
+ .unwrap_or_else(|| display_label(id))
+}
+
/// Plain (unscored) list of children that have no votes yet.
-fn unranked_list(label: &str, items: &[ItemId]) -> Markup {
+fn unranked_list(label: &str, items: &[ItemId], tree: &GlobalTree) -> Markup {
html! {
@if !items.is_empty() {
h3 class="rank-heading muted small" { (label) }
@@ -191,7 +198,7 @@ fn unranked_list(label: &str, items: &[ItemId]) -> Markup {
@for it in items {
li {
a href=(item_href(it)) {
- strong { (display_label(it)) }
+ strong { (child_label(tree, it)) }
}
}
}
@@ -200,7 +207,7 @@ fn unranked_list(label: &str, items: &[ItemId]) -> Markup {
}
}
-pub fn ranking_panel(item: &ItemId, node: &NodeState) -> Markup {
+pub fn ranking_panel(item: &ItemId, node: &NodeState, tree: &GlobalTree) -> Markup {
let group = &node.local_ranking;
let n = group.idx_to_item.len();
let (comps, _isolates) =
@@ -248,7 +255,7 @@ pub fn ranking_panel(item: &ItemId, node: &NodeState) -> Markup {
@let label = if multi { format!("Ranking group {}", gi + 1) } else { "Ranking".to_string() };
(rank_list(&label, ranked, 1))
}
- (unranked_list("Unranked", &unranked))
+ (unranked_list("Unranked", &unranked, tree))
}
}
}
@@ -297,7 +304,7 @@ async fn item_page(state: AppState, uri: Uri, item: ItemId) -> Markup {
(input_panel("", None))
(breadcrumb_path(&item))
(entity_section(&item, node, false))
- (ranking_panel(&item, node))
+ (ranking_panel(&item, node, &tree))
};
layout("sorter2", body, views)
}
diff --git a/server/src/reddit.rs b/server/src/reddit.rs
index a0eb688709478ee0185b953b41a5d26cc354764d..69d979bc7e4a1cb078f70114dc539bdc1986b574 100644
--- a/server/src/reddit.rs
+++ b/server/src/reddit.rs
@@ -300,9 +300,16 @@ async fn reddit_worker(
}
{
let mut tree = tree.write().await;
- apply_entity_import(&mut tree, &child_id, child_payload);
if kind == FetchKind::Children {
- tree.link_child(&fetch_id, &child_id);
+ let view = entity_view_from_payload(&child_id, &child_payload);
+ tree.apply_entity_under_parent(
+ &fetch_id,
+ &child_id,
+ child_payload,
+ view,
+ );
+ } else {
+ apply_entity_import(&mut tree, &child_id, child_payload);
}
}
written += 1;
diff --git a/server/src/reducer.rs b/server/src/reducer.rs
index a36cd5c9287d61536f9f4a3f6b0df2342388857a..4e42d0369dab50bb2f8ca664aa69b628292f6c07 100644
--- a/server/src/reducer.rs
+++ b/server/src/reducer.rs
@@ -209,14 +209,24 @@ impl GlobalTree {
}
}
- /// Directly attach `child` under `parent`, bypassing path-based nesting.
- /// Used for imported listings (e.g. a subreddit's posts) so they show up
- /// as children of the subreddit rather than a deep `…/comments/<id>` path.
- pub fn link_child(&mut self, parent: &ItemId, child: &ItemId) {
+ /// Import entity data for `id` and attach it as a direct child of `parent`
+ /// without running [`Self::ensure_path`] on `id` (avoids Reddit `/comments/`
+ /// parent rules pulling intermediate path segments into the subreddit).
+ pub fn apply_entity_under_parent(
+ &mut self,
+ parent: &ItemId,
+ id: &ItemId,
+ payload: Value,
+ view: Option<EntityData>,
+ ) {
self.ensure_path(parent);
- self.ensure_path(child);
+ self.ensure_node(id);
+ if let Some(node) = self.nodes.get_mut(id) {
+ node.entity_raw = Some(payload);
+ node.data = view;
+ }
if let Some(p) = self.nodes.get_mut(parent) {
- p.children.insert(child.clone());
+ p.children.insert(id.clone());
}
}
}
diff --git a/test/reddit_import.clj b/test/reddit_import.clj
index 84cbdcf7965e50290313cbce2243a16b583d2097..45a2a19f20799d77e84d8aa64735ab5e7e45f97c 100644
--- a/test/reddit_import.clj
+++ b/test/reddit_import.clj
@@ -67,6 +67,36 @@
(do (Thread/sleep 200) (recur))
false)))))
+(defn- run-reddit-fetch-assertions [app-base data-dir]
+ (let [browse-url (str app-base "/~/https://reddit.com/r/rust")
+ log-path (str data-dir "/events.jsonl")
+ before (:out (process/shell {:out :string :err :string}
+ "curl" "-sf" browse-url))]
+ (is (str/includes? before "Fetch from Reddit"))
+ (is (not (str/includes? before "The Rust Programming Language")))
+ (let [sse (curl-fetch-ui-sse app-base "reddit.com/r/rust" "self")]
+ (is (zero? (:exit sse)) "POST /ui fetch_entity (self) SSE succeeds")
+ (is (str/includes? (:out sse) "Idiomorph.morph"))
+ (is (str/includes? (:out sse) "The Rust Programming Language"))
+ (is (wait-event-log log-path 2000) "event log written"))
+ (let [after (:out (process/shell {:out :string :err :string}
+ "curl" "-sf" browse-url))
+ log (slurp (io/file log-path))]
+ (is (str/includes? after "The Rust Programming Language"))
+ (is (str/includes? log "\"type\":\"entity_imported\""))
+ (is (str/includes? log "\"subscribers\":350000"))
+ (is (str/includes? log "\"display_name\":\"rust\"")))
+ (let [children-sse (curl-fetch-ui-sse app-base "reddit.com/r/rust" "children")]
+ (is (zero? (:exit children-sse)) "POST /ui fetch_entity (children) SSE succeeds")
+ (is (str/includes? (:out children-sse) "Idiomorph.morph"))
+ (is (str/includes? (:out children-sse) "Announcing Rust 1.99")))
+ (let [after-children (:out (process/shell {:out :string :err :string}
+ "curl" "-sf" browse-url))
+ log2 (slurp (io/file log-path))]
+ (is (str/includes? after-children "Announcing Rust 1.99"))
+ (is (str/includes? after-children "Unranked"))
+ (is (str/includes? log2 "announcing_rust_199")))))
+
(deftest reddit-fetch-via-mock-api
(testing "Fetch more queues import; event log stores full payload; page shows title"
(let [root (repo-root)
@@ -102,24 +132,7 @@
bin)]
(try
(is (wait-health app-base 20000) "app healthz")
- (let [browse-url (str app-base "/~/https://reddit.com/r/rust")
- before (:out (process/shell {:out :string :err :string}
- "curl" "-sf" browse-url))]
- (is (str/includes? before "Fetch from Reddit"))
- (is (not (str/includes? before "The Rust Programming Language")))
- (let [log-path (str data-dir "/events.jsonl")
- sse (curl-fetch-ui-sse app-base "reddit.com/r/rust")]
- (is (zero? (:exit sse)) "POST /ui fetch_entity SSE succeeds")
- (is (str/includes? (:out sse) "event: complete"))
- (is (str/includes? (:out sse) "The Rust Programming Language"))
- (is (wait-event-log log-path 2000) "event log written")
- (let [after (:out (process/shell {:out :string :err :string}
- "curl" "-sf" browse-url))
- log (slurp (io/file log-path))]
- (is (str/includes? after "The Rust Programming Language"))
- (is (str/includes? log "\"type\":\"entity_imported\""))
- (is (str/includes? log "\"subscribers\":350000"))
- (is (str/includes? log "\"display_name\":\"rust\"")))))
+ (run-reddit-fetch-assertions app-base data-dir)
(finally
(process/destroy proc))))
(finally
diff --git a/test/smoke.clj b/test/smoke.clj
index 11887c48282088e140d823a88ba616f6325835b3..ce9f958c84b9a89ae55e215ab519f1df6435e24b 100644
--- a/test/smoke.clj
+++ b/test/smoke.clj
@@ -49,7 +49,7 @@
(is (wait-health base 15000) "server responds to /healthz")
(let [home (:out (process/shell {:out :string :err :string}
"curl" "-sf" (str base "/")))]
- (is (str/includes? home "vote-panel"))
+ (is (str/includes? home "entity-section"))
(is (str/includes? home "ranking-panel"))
(is (str/includes? home "parser-panel"))
(is (str/includes? home "__rpc__")))
B — c_c0df72aee6da (tommy-mor)
message
[bf118bdf] Sanitize Reddit entity body HTML before rendering. Use ammonia at render time so untrusted selftext_html cannot execute scripts in our origin. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/Cargo.lock b/Cargo.lock
index 3dec7cb72a182dc654a37dca8ba0b49d77504daa..0dd4fce5fb6400ae153cca4e3dbf5a5158e6d8b4 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -11,6 +11,19 @@ dependencies = [
"memchr",
]
+[[package]]
+name = "ammonia"
+version = "4.1.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "17e913097e1a2124b46746c980134e8c954bc17a6a59bb3fde96f088d126dde6"
+dependencies = [
+ "cssparser",
+ "html5ever",
+ "maplit",
+ "tendril",
+ "url",
+]
+
[[package]]
name = "anyhow"
version = "1.0.102"
@@ -355,6 +368,29 @@ version = "0.2.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5"
+[[package]]
+name = "cssparser"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4e901edd733a1472f944a45116df3f846f54d37e67e68640ac8bb69689aca2aa"
+dependencies = [
+ "cssparser-macros",
+ "dtoa-short",
+ "itoa",
+ "phf",
+ "smallvec",
+]
+
+[[package]]
+name = "cssparser-macros"
+version = "0.6.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "13b588ba4ac1a99f7f2964d24b3d896ddc6bf847ee3855dbd4366f058cfcd331"
+dependencies = [
+ "quote",
+ "syn",
+]
+
[[package]]
name = "deranged"
version = "0.5.8"
@@ -381,6 +417,21 @@ version = "0.15.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1aaf95b3e5c8f23aa320147307562d361db0ae0d51242340f558153b4eb2439b"
+[[package]]
+name = "dtoa"
+version = "1.0.11"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4c3cf4824e2d5f025c7b531afcb2325364084a16806f6d47fbc1f5fbd9960590"
+
+[[package]]
+name = "dtoa-short"
+version = "0.3.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "cd1511a7b6a56299bd043a9c167a6d2bfb37bf84a6dfceaba651168adfb43c87"
+dependencies = [
+ "dtoa",
+]
+
[[package]]
name = "durable"
version = "0.2.0"
@@ -482,6 +533,16 @@ dependencies = [
"percent-encoding",
]
+[[package]]
+name = "futf"
+version = "0.1.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "df420e2e84819663797d1ec6544b13c5be84629e7bb00dc960d6917db2987843"
+dependencies = [
+ "mac",
+ "new_debug_unreachable",
+]
+
[[package]]
name = "futures-channel"
version = "0.3.32"
@@ -614,6 +675,17 @@ version = "0.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea"
+[[package]]
+name = "html5ever"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "55d958c2f74b664487a2035fe1dadb032c48718a03b63f3ab0b8537db8549ed4"
+dependencies = [
+ "log",
+ "markup5ever",
+ "match_token",
+]
+
[[package]]
name = "http"
version = "1.4.1"
@@ -974,6 +1046,15 @@ version = "0.8.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0"
+[[package]]
+name = "lock_api"
+version = "0.4.14"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "224399e74b87b5f3557511d98dff8b14089b3dadafcab6bb93eab67d3aace965"
+dependencies = [
+ "scopeguard",
+]
+
[[package]]
name = "log"
version = "0.4.30"
@@ -990,6 +1071,40 @@ dependencies = [
"libc",
]
+[[package]]
+name = "mac"
+version = "0.1.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c41e0c4fef86961ac6d6f8a82609f55f31b05e4fce149ac5710e439df7619ba4"
+
+[[package]]
+name = "maplit"
+version = "1.0.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3e2e65a1a2e43cfcb47a895c4c8b10d1f4a61097f9f254f183aee60cad9c651d"
+
+[[package]]
+name = "markup5ever"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "311fe69c934650f8f19652b3946075f0fc41ad8757dbb68f1ca14e7900ecc1c3"
+dependencies = [
+ "log",
+ "tendril",
+ "web_atoms",
+]
+
+[[package]]
+name = "match_token"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ac84fd3f360fcc43dc5f5d186f02a94192761a080e8bc58621ad4d12296a58cf"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
[[package]]
name = "matchers"
version = "0.2.0"
@@ -1092,6 +1207,12 @@ dependencies = [
"tempfile",
]
+[[package]]
+name = "new_debug_unreachable"
+version = "1.0.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "650eef8c711430f1a879fdd01d4745a7deea475becfb90269c06775983bbf086"
+
[[package]]
name = "nom"
version = "7.1.3"
@@ -1175,6 +1296,29 @@ dependencies = [
"vcpkg",
]
+[[package]]
+name = "parking_lot"
+version = "0.12.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "93857453250e3077bd71ff98b6a65ea6621a19bb0f559a85248955ac12c45a1a"
+dependencies = [
+ "lock_api",
+ "parking_lot_core",
+]
+
+[[package]]
+name = "parking_lot_core"
+version = "0.9.12"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1"
+dependencies = [
+ "cfg-if",
+ "libc",
+ "redox_syscall",
+ "smallvec",
+ "windows-link",
+]
+
[[package]]
name = "peeking_take_while"
version = "0.1.2"
@@ -1187,6 +1331,58 @@ version = "2.3.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220"
+[[package]]
+name = "phf"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "1fd6780a80ae0c52cc120a26a1a42c1ae51b247a253e4e06113d23d2c2edd078"
+dependencies = [
+ "phf_macros",
+ "phf_shared",
+]
+
+[[package]]
+name = "phf_codegen"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "aef8048c789fa5e851558d709946d6d79a8ff88c0440c587967f8e94bfb1216a"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+]
+
+[[package]]
+name = "phf_generator"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3c80231409c20246a13fddb31776fb942c38553c51e871f8cbd687a4cfb5843d"
+dependencies = [
+ "phf_shared",
+ "rand 0.8.6",
+]
+
+[[package]]
+name = "phf_macros"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f84ac04429c13a7ff43785d75ad27569f2951ce0ffd30a3321230db2fc727216"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
+[[package]]
+name = "phf_shared"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "67eabc2ef2a60eb7faa00097bd1ffdb5bd28e62bf39990626a582201b7a754e5"
+dependencies = [
+ "siphasher",
+]
+
[[package]]
name = "pin-project-lite"
version = "0.2.17"
@@ -1223,6 +1419,12 @@ dependencies = [
"zerocopy",
]
+[[package]]
+name = "precomputed-hash"
+version = "0.1.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "925383efa346730478fb4838dbe9137d2a47675ad789c546d150a6e1dd4ab31c"
+
[[package]]
name = "prettyplease"
version = "0.2.37"
@@ -1379,6 +1581,15 @@ dependencies = [
"rand_core 0.9.5",
]
+[[package]]
+name = "redox_syscall"
+version = "0.5.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ed2bf2547551a7053d6fdfafda3f938979645c44812fbfcda098faae3f1a362d"
+dependencies = [
+ "bitflags 2.11.1",
+]
+
[[package]]
name = "regex"
version = "1.12.3"
@@ -1563,6 +1774,12 @@ dependencies = [
"windows-sys 0.61.2",
]
+[[package]]
+name = "scopeguard"
+version = "1.2.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49"
+
[[package]]
name = "security-framework"
version = "3.7.0"
@@ -1683,6 +1900,12 @@ dependencies = [
"libc",
]
+[[package]]
+name = "siphasher"
+version = "1.0.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "8ee5873ec9cce0195efcb7a4e9507a04cd49aec9c83d0389df45b1ef7ba2e649"
+
[[package]]
name = "slab"
version = "0.4.12"
@@ -1709,6 +1932,7 @@ dependencies = [
name = "sorter2-server"
version = "0.0.1"
dependencies = [
+ "ammonia",
"async-stream",
"axum",
"axum-extra",
@@ -1742,6 +1966,31 @@ version = "1.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596"
+[[package]]
+name = "string_cache"
+version = "0.8.9"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "bf776ba3fa74f83bf4b63c3dcbbf82173db2632ed8452cb2d891d33f459de70f"
+dependencies = [
+ "new_debug_unreachable",
+ "parking_lot",
+ "phf_shared",
+ "precomputed-hash",
+ "serde",
+]
+
+[[package]]
+name = "string_cache_codegen"
+version = "0.5.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c711928715f1fe0fe509c53b43e993a9a557babc2d0a3567d0a3006f1ac931a0"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+ "proc-macro2",
+ "quote",
+]
+
[[package]]
name = "subtle"
version = "2.6.1"
@@ -1813,6 +2062,17 @@ dependencies = [
"windows-sys 0.61.2",
]
+[[package]]
+name = "tendril"
+version = "0.4.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "d24a120c5fc464a3458240ee02c299ebcb9d67b5249c8848b09d639dca8d7bb0"
+dependencies = [
+ "futf",
+ "mac",
+ "utf-8",
+]
+
[[package]]
name = "thiserror"
version = "1.0.69"
@@ -2116,6 +2376,12 @@ version = "2.1.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da"
+[[package]]
+name = "utf-8"
+version = "0.7.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "09cc8ee72d2a9becf2f2febe0205bbed8fc6615b7cb429ad062dc7b7ddd036a9"
+
[[package]]
name = "utf8_iter"
version = "1.0.4"
@@ -2281,6 +2547,18 @@ dependencies = [
"wasm-bindgen",
]
+[[package]]
+name = "web_atoms"
+version = "0.1.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "57ffde1dc01240bdf9992e3205668b235e59421fd085e8a317ed98da0178d414"
+dependencies = [
+ "phf",
+ "phf_codegen",
+ "string_cache",
+ "string_cache_codegen",
+]
+
[[package]]
name = "windows-link"
version = "0.2.1"
diff --git a/server/Cargo.toml b/server/Cargo.toml
index 47659ff82fbfb50972eb2b87575e80f66e572ba4..27f552c20b97ef28cdde4cb6b1a4980375135111 100644
--- a/server/Cargo.toml
+++ b/server/Cargo.toml
@@ -13,6 +13,7 @@ serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "1"
maud = { version = "0.26", features = ["axum"] }
+ammonia = "4.1"
tower = "0.5"
tower-http = { version = "0.5", features = ["trace"] }
tracing = "0.1"
diff --git a/server/src/fetch/html.rs b/server/src/fetch/html.rs
index dadf050515f0473943dad97df5d318032c8cb385..5b160c6b8bd216dfaf80149854aec0566cd00460 100644
--- a/server/src/fetch/html.rs
+++ b/server/src/fetch/html.rs
@@ -4,6 +4,7 @@ use maud::{html, Markup};
use crate::{
form_template::template_json_compact,
+ html::sanitize::entity_body_html,
path_types::ItemId,
reddit::{is_children_fetchable, is_fetchable},
reducer::NodeState,
@@ -27,7 +28,7 @@ pub fn entity_panel(node: &NodeState) -> Markup {
p class="muted small" { "by " (author) }
}
@if let Some(body) = &data.body_html {
- div class="entity-body" { (maud::PreEscaped(body)) }
+ div class="entity-body" { (maud::PreEscaped(entity_body_html(body))) }
}
}
}
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index e180a0ca542a33e2300c0a4809e6b9cfee07ecfe..a58cbbee3490a08a625cb06df06848c59a615d65 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -20,6 +20,7 @@ use crate::{
ui
… preview truncated; 2,223 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.