You are a constitutional council ranking individual git commits for ownership allocation. Compare these two commits. Decide which contributed more lasting value to the project. Judge substance, not spectacle: - Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise. - Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one. - Do not favor a side merely because its patch is longer or noisier. - Weight what the change does for the project, not the contributor's name. Return ONLY a JSON object: {"winner": "A" or "B", "ratio": "N:M", "explanation": "..."} The explanation must cite concrete differences in the patches (1-3 sentences). Side A — contributor: tommy-mor Side A — commit message: [880eb778] Harden auth: fail-closed votes, mock OAuth gate, Secure cookies. Also show the current alias in the top nav and pin durable by rev. Co-authored-by: Cursor Side A — unified diff (full patch): diff --git a/AGENTS.md b/AGENTS.md index babb889d6fbfb1fa7176c9e6b7544ae17b61dd2e..6e0fd8ebb65d665c9c1438e3275971d62b98fd95 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -10,11 +10,11 @@ Single Rust web app **`sorter2-server`**: pairwise voting, rank-centrality ranki - **Bootstrap script**: `./scripts/cursor-env-install.sh` (also run via `.cursor/environment.json` on Cloud Agent boot) installs Playwright Chromium, Babashka, bbin, `clj-paren-repair`, and warms the RocksDB build. - **Rust 1.88+** is required (`rust-toolchain.toml`). The Cloud Dockerfile and `cursor-env-install.sh` install **rustup** 1.88.0 first so `cargo` works while Playwright/Clojure bootstrap continues. Do not rely on `/usr/local/cargo` (often missing or stale). -- **RocksDB / `durable`**: Ubuntu’s default `c++` is often **clang** without libc++ headers. Set **`CXX=g++`** and **`RUSTFLAGS="-C linker=g++"`** (or `CC=gcc`) before `cargo build` / `cargo test` — both are set in the bootstrap script and `.cursor/environment.json`. +- **RocksDB / `durable`**: `durable` is an external git dependency (`tommy-mor/durable`, pinned by rev in `server/Cargo.toml`). Ubuntu’s default `c++` is often **clang** without libc++ headers. Set **`CXX=g++`** and **`RUSTFLAGS="-C linker=g++"`** (or `CC=gcc`) before `cargo build` / `cargo test` — both are set in the bootstrap script and `.cursor/environment.json`. - **System packages** for builds: `build-essential`, `g++`, `clang`, `libclang-dev`, `pkg-config`, `libssl-dev`, `openjdk-21-jre-headless` (for `reqwest` / OpenSSL, `librocksdb-sys`, `zstd-sys` / bindgen, and **bbin** / Clojure JVM). The bootstrap sets **`JAVA_HOME`** when Java is present. - **Clojure CLI 1.12.0.1530** (used in CI): install from https://clojure.org/guides/install_clojure — needed for `./scripts/clj-test.sh` / Kaocha tests. - **Babashka / bbin / clj-paren-repair**: installed by `cursor-env-install.sh` into `~/.local/bin` (bb tasks in `bb.edn`, delimiter repair for Clojure edits). -- **Playwright** (Spel browser tests in `test/vote_compare.clj`): Chromium via `clojure -M -e "(com.microsoft.playwright.CLI/main ...)"` — run once after clone or use the bootstrap script. +- **Playwright** (Spel browser tests in `test/vote_compare.clj` / `test/auth_login.clj`): Chromium via `clojure -M -e "(com.microsoft.playwright.CLI/main ...)"` — run once after clone or use the bootstrap script. ### Commands (see also `TEST.sh`) @@ -34,13 +34,17 @@ Environment variables (defaults in `server/src/state.rs`): - `PORT` — default `8080` - `SORTER2_DATA_DIR` — default `./data` (created on startup) - `SORTER2_EVENT_LOG` — default `{data_dir}/events.jsonl` +- `SORTER2_BASE_URL` — public origin (also drives Secure cookies when `https://`) +- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth (optional; login disabled if unset) +- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` (tests only) Health check: `GET /healthz` → `ok`. -Core UI flow: `POST /ui` with form field `__rpc__` (JSON). Example vote: +Core UI flow: `POST /ui` with form field `__rpc__` (JSON). Votes require a session cookie (sign in via `/login`). Example vote: ```bash curl -sf -X POST http://127.0.0.1:8080/ui \ + --cookie "sorter2_session=..." \ --data-urlencode '__rpc__={"action":"record_vote","a":"alpha","b":"beta","ratio_left":2,"ratio_right":1}' ``` diff --git a/Cargo.lock b/Cargo.lock index aa02997ad85777195f135bfd9456bcee0fc9a590..1f8690f3e486d099577a32c2ece48caf57ea7160 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -414,7 +414,7 @@ dependencies = [ [[package]] name = "durable" version = "0.2.0" -source = "git+https://github.com/tommy-mor/durable.git?branch=main#a6c14eaa809693140eea0c22b07ef24d8e74adaf" +source = "git+https://github.com/tommy-mor/durable.git?rev=a6c14eaa809693140eea0c22b07ef24d8e74adaf#a6c14eaa809693140eea0c22b07ef24d8e74adaf" dependencies = [ "ciborium", "durable-derive", @@ -426,7 +426,7 @@ dependencies = [ [[package]] name = "durable-derive" version = "0.2.0" -source = "git+https://github.com/tommy-mor/durable.git?branch=main#a6c14eaa809693140eea0c22b07ef24d8e74adaf" +source = "git+https://github.com/tommy-mor/durable.git?rev=a6c14eaa809693140eea0c22b07ef24d8e74adaf#a6c14eaa809693140eea0c22b07ef24d8e74adaf" dependencies = [ "proc-macro2", "quote", diff --git a/server/Cargo.toml b/server/Cargo.toml index dfa39beddecfa37dcdeaa602cb30f4b547528fbb..bd88687fb0ba47d68f2c08eb5e11d0e08b7c4398 100644 --- a/server/Cargo.toml +++ b/server/Cargo.toml @@ -25,7 +25,7 @@ futures-util = { version = "0.3", default-features = false, features = ["std"] } rand = "0.8" urlencoding = "2" url = "2" -durable = { git = "https://github.com/tommy-mor/durable.git", branch = "main" } +durable = { git = "https://github.com/tommy-mor/durable.git", rev = "a6c14eaa809693140eea0c22b07ef24d8e74adaf" } [dev-dependencies] reqwest = { version = "0.12", features = ["json"] } diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs index b86581b1f337650564274254d840e8a75b49524d..9da62ffbed07eb28729aa3160bf33b07ce0d7945 100644 --- a/server/src/api/ui_html.rs +++ b/server/src/api/ui_html.rs @@ -71,10 +71,16 @@ pub async fn post_ui_html( return resp; } let parent = parent_from_scope(&scope); - let actor = resolve_vote_actor( + let actor = match resolve_vote_actor( state.projection_store.db(), session_id_from_jar(&jar).as_deref(), - ); + ) { + Ok(actor) => actor, + Err(_) => { + return vote_auth_redirect(&state, &jar) + .unwrap_or_else(|| login_redirect_js().into_response()); + } + }; if let Err(e) = state .record_vote(&parent, &a, &b, ratio_left, ratio_right, &actor) .await diff --git a/server/src/auth/config.rs b/server/src/auth/config.rs index a1f042c655bf3e5234eeb87a7d889f64592807fb..a5976af9a52ea207b35ae87bd1fe927c47a477ca 100644 --- a/server/src/auth/config.rs +++ b/server/src/auth/config.rs @@ -1,9 +1,42 @@ pub const AUTH_RETURN_COOKIE: &str = "sorter2_auth_return"; +/// Allow `mock_user` on `/auth/github` (test harness only). +pub fn mock_oauth_allowed() -> bool { + matches!( + std::env::var("SORTER2_ALLOW_MOCK_OAUTH").as_deref(), + Ok("1") | Ok("true") | Ok("TRUE") + ) +} + +/// Set the Secure flag on auth cookies when serving over HTTPS. +pub fn cookies_secure() -> bool { + std::env::var("SORTER2_BASE_URL") + .map(|u| u.starts_with("https://")) + .unwrap_or(false) +} + pub fn sanitize_return_to(raw: &str) -> String { let s = raw.trim(); - if s.is_empty() || !s.starts_with('/') || s.starts_with("//") { + if s.is_empty() || !s.starts_with('/') || s.starts_with("//") || s.starts_with("/\\") { + return "/".to_string(); + } + // Reject scheme-relative and protocol-smuggling forms. + if s.contains("://") || s.contains('\\') { return "/".to_string(); } s.to_string() } + +#[cfg(test)] +mod tests { + use super::*; + + #[test] + fn sanitize_return_to_blocks_open_redirects() { + assert_eq!(sanitize_return_to(""), "/"); + assert_eq!(sanitize_return_to("//evil.com"), "/"); + assert_eq!(sanitize_return_to("/\\evil.com"), "/"); + assert_eq!(sanitize_return_to("https://evil.com"), "/"); + assert_eq!(sanitize_return_to("/vote?parent=x"), "/vote?parent=x"); + } +} diff --git a/server/src/auth/mod.rs b/server/src/auth/mod.rs index 5ed535ba199fa736f0048c32623b14c3b1e5de2d..d4a85ef52c15dc35148e4c743f0d646cbbdb056d 100644 --- a/server/src/auth/mod.rs +++ b/server/src/auth/mod.rs @@ -26,7 +26,7 @@ use crate::{ ui_action::UI_RPC_FIELD, }; -pub use session::{resolve_vote_actor, session_id_from_jar, VoteActor}; +pub use session::{nav_pseudonym, resolve_vote_actor, session_id_from_jar, VoteActor}; pub fn base_url_from_env(port: u16) -> String { std::env::var("SORTER2_BASE_URL") @@ -168,6 +168,10 @@ pub async fn login_page( "login · sorter2", login_body(session.as_ref(), &aliases, &providers), state.views.get_views("/login"), + session + .as_ref() + .filter(|s| !s.pseudonym.trim().is_empty()) + .map(|s| s.pseudonym.as_str()), ); (jar, Html(markup.into_string())).into_response() } @@ -222,6 +226,7 @@ pub async fn alias_page( "choose alias · sorter2", body, state.views.get_views("/login/alias"), + None, ) .into_string(), ) @@ -237,7 +242,12 @@ pub async fn github_start( .ok_or(StatusCode::SERVICE_UNAVAILABLE)?; let return_to = return_from_query_or_jar(&jar, query.return_to.as_deref()); let state_token = session::new_oauth_state(); - let url = oauth::authorize_url(&cfg, &state_token, query.mock_user.as_deref()); + let mock_user = if config::mock_oauth_allowed() { + query.mock_user.as_deref() + } else { + None + }; + let url = oauth::authorize_url(&cfg, &state_token, mock_user); let jar = jar .add(session::oauth_state_cookie_value(&state_token)) .add(session::auth_return_cookie_value(&return_to)); diff --git a/server/src/auth/session.rs b/server/src/auth/session.rs index 09659240b9455c6fca12db5652e1d31cf8c2acfc..41df030ded3abcafc0ab3887ab769adf103f9aa0 100644 --- a/server/src/auth/session.rs +++ b/server/src/auth/session.rs @@ -5,7 +5,7 @@ use durable::{Db, Durability}; use rand::Rng; use crate::{ - auth::config::AUTH_RETURN_COOKIE, + auth::config::{self, AUTH_RETURN_COOKIE}, fetch::now_ms, identity::{DEFAULT_ACTOR_UUID, DEFAULT_PSEUDONYM}, storage_dto::{SessionDataV1, SESSION_DATA_VERSION}, @@ -37,6 +37,7 @@ pub struct VoteActor { } impl VoteActor { + /// Test / bench helper: seed votes as the default pseudonym without a session. pub fn anon() -> Self { Self { pseudonym: DEFAULT_PSEUDONYM.to_string(), @@ -70,20 +71,51 @@ fn hex_encode(bytes: &[u8]) -> String { bytes.iter().map(|b| format!("{b:02x}")).collect() } -pub fn resolve_vote_actor(db: &Db, session_id: Option<&str>) -> VoteActor { - let Some(session_id) = session_id else { - return VoteActor::anon(); - }; - let Ok(Some(session)) = load_session(db, session_id) else { - return VoteActor::anon(); - }; - if session.expires_at <= now_ms() { - return VoteActor::anon(); +fn build_cookie(name: &'static str, value: String) -> Cookie<'static> { + let mut builder = Cookie::build((name, value)) + .http_only(true) + .same_site(SameSite::Lax) + .path("/"); + if config::cookies_secure() { + builder = builder.secure(true); + } + builder.build() +} + +fn clear_cookie(name: &'static str) -> Cookie<'static> { + let mut builder = Cookie::build((name, "")) + .http_only(true) + .same_site(SameSite::Lax) + .path("/") + .removal(); + if config::cookies_secure() { + builder = builder.secure(true); + } + builder.build() +} + +/// Resolve the vote actor from a live session. Fail-closed: never falls back to anon. +pub fn resolve_vote_actor(db: &Db, session_id: Option<&str>) -> Result { + let session_id = session_id.ok_or("sign in to vote")?; + let session = load_valid_session(db, session_id).ok_or("session expired")?; + if !session_has_pseudonym(&session) { + return Err("choose an alias first"); } let trust_weight = user_trust_weight(db, &session.uuid).unwrap_or(1.0); - VoteActor { + Ok(VoteActor { pseudonym: session.current_pseudonym, trust_weight, + }) +} + +/// Display name for the top nav, if any session is active. +pub fn nav_pseudonym(db: &Db, jar: &CookieJar) -> Option { + let session_id = session_id_from_jar(jar)?; + let session = load_valid_session(db, &session_id)?; + if session_has_pseudonym(&session) { + Some(session.current_pseudonym) + } else { + None } } @@ -151,54 +183,27 @@ pub fn destroy_session(db: &Db, session_id: &str) -> Result<(), String> { } pub fn session_cookie_value(session_id: &str) -> Cookie<'static> { - Cookie::build((SESSION_COOKIE, session_id.to_string())) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .build() + build_cookie(SESSION_COOKIE, session_id.to_string()) } pub fn clear_session_cookie() -> Cookie<'static> { - Cookie::build((SESSION_COOKIE, "")) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .removal() - .build() + clear_cookie(SESSION_COOKIE) } pub fn oauth_state_cookie_value(state: &str) -> Cookie<'static> { - Cookie::build((OAUTH_STATE_COOKIE, state.to_string())) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .build() + build_cookie(OAUTH_STATE_COOKIE, state.to_string()) } pub fn clear_oauth_state_cookie() -> Cookie<'static> { - Cookie::build((OAUTH_STATE_COOKIE, "")) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .removal() - .build() + clear_cookie(OAUTH_STATE_COOKIE) } pub fn auth_return_cookie_value(return_to: &str) -> Cookie<'static> { - Cookie::build((AUTH_RETURN_COOKIE, return_to.to_string())) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .build() + build_cookie(AUTH_RETURN_COOKIE, return_to.to_string()) } pub fn clear_auth_return_cookie() -> Cookie<'static> { - Cookie::build((AUTH_RETURN_COOKIE, "")) - .http_only(true) - .same_site(SameSite::Lax) - .path("/") - .removal() - .build() + clear_cookie(AUTH_RETURN_COOKIE) } pub fn auth_return_from_jar(jar: &CookieJar) -> Option { @@ -213,28 +218,35 @@ pub fn oauth_state_from_jar(jar: &CookieJar) -> Option { jar.get(OAUTH_STATE_COOKIE).map(|c| c.value().to_string()) } -pub fn actor_uuid_for_vote(db: &Db, session_id: Option<&str>) -> String { - let Some(session_id) = session_id else { - return DEFAULT_ACTOR_UUID.to_string(); - }; - load_session(db, session_id) - .ok() - .flatten() - .filter(|s| s.expires_at > now_ms()) - .map(|s| s.uuid) - .unwrap_or_else(|| DEFAULT_ACTOR_UUID.to_string()) -} - #[cfg(test)] mod tests { use super::*; #[test] - fn missing_session_falls_back_to_anon() { + fn missing_session_is_error() { + let dir = tempfile::tempdir().unwrap(); + let db = Db::open(dir.path()).unwrap(); + assert_eq!(resolve_vote_actor(&db, None).unwrap_err(), "sign in to vote"); + } + + #[test] + fn session_without_pseudonym_is_error() { + let dir = tempfile::tempdir().unwrap(); + let db = Db::open(dir.path()).unwrap(); + let (id, _) = create_session(&db, DEFAULT_ACTOR_UUID, "").unwrap(); + assert_eq!( + resolve_vote_actor(&db, Some(&id)).unwrap_err(), + "choose an alias first" + ); + } + + #[test] + fn session_with_pseudonym_resolves() { let dir = tempfile::tempdir().unwrap(); let db = Db::open(dir.path()).unwrap(); - let actor = resolve_vote_actor(&db, None); - assert_eq!(actor.pseudonym, DEFAULT_PSEUDONYM); + let (id, _) = create_session(&db, DEFAULT_ACTOR_UUID, "alice").unwrap(); + let actor = resolve_vote_actor(&db, Some(&id)).unwrap(); + assert_eq!(actor.pseudonym, "alice"); assert_eq!(actor.trust_weight, 1.0); } } diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs index 46d18b87f1313bf0aeb29955d18f291961057509..3cc3d7bdf55b5cb5d009600f4ade1fcd201a410b 100644 --- a/server/src/html/mod.rs +++ b/server/src/html/mod.rs @@ -4,11 +4,13 @@ use axum::{ http::{header, StatusCode, Uri}, response::{IntoResponse, Response}, }; +use axum_extra::extract::cookie::CookieJar; use maud::{html, Markup, DOCTYPE}; use std::collections::HashSet; use crate::{ + auth::nav_pseudonym, fetch::html::entity_section, form_template::template_json_compact, path_types::ItemId, @@ -126,7 +128,7 @@ pub fn now_ms() -> i64 { t.as_millis() as i64 } -pub(crate) fn layout(title: &str, body: Markup, views: u64) -> Markup { +pub(crate) fn layout(title: &str, body: Markup, views: u64, nav_user: Option<&str>) -> Markup { let ver = asset_version(); let css_href = format!("/static/sorter.css?v={ver}"); let js_src = format!("/static/sorter_ui.js?v={ver}"); @@ -145,7 +147,15 @@ pub(crate) fn layout(title: &str, body: Markup, views: u64) -> Markup { span class="view-meta muted" { (views) " views" } } nav class="top-nav" { - a href="/login" { "login" } + @if let Some(name) = nav_user { + span class="top-nav-user" data-testid="nav-user" { (name) } + a href="/login" { "account" } + form class="top-nav-logout" method="post" action="/auth/logout" data-navigate="full" { + button type="submit" data-testid="nav-logout" { "log out" } + } + } @else { + a href="/login" data-testid="nav-login" { "login" } + } } div id="errors" {} (body) @@ -481,10 +491,11 @@ pub fn input_panel(query: &str, error: Option<&str>) -> Markup { } } -async fn item_page(state: AppState, uri: Uri, item: ItemId) -> Markup { +async fn item_page(state: AppState, uri: Uri, item: ItemId, jar: CookieJar) -> Markup { let path = uri.path().to_string(); state.views.increment(path.clone()); let views = state.views.get_views(&path); + let nav_user = nav_pseudonym(state.projection_store.db(), &jar); let tree = state .scope_tree(&item) @@ -513,16 +524,24 @@ async fn item_page(state: AppState, uri: Uri, item: ItemId) -> Markup { (ranking_panel(&item, node, &tree)) } }; - layout("sorter2", body, views) + layout("sorter2", body, views, nav_user.as_deref()) } -pub async fn home(State(state): State, uri: Uri) -> impl IntoResponse { - item_page(state, uri, ItemId::root()).await +pub async fn home( + State(state): State, + jar: CookieJar, + uri: Uri, +) -> impl IntoResponse { + item_page(state, uri, ItemId::root(), jar).await } -pub async fn browse(State(state): State, uri: Uri) -> impl IntoResponse { +pub async fn browse( + State(state): State, + jar: CookieJar, + uri: Uri, +) -> impl IntoResponse { let item = ItemId::from_browse_uri(uri.path()).unwrap_or(ItemId::root()); - item_page(state, uri, item).await + item_page(state, uri, item, jar).await } #[cfg(test)] diff --git a/server/src/html/vote.rs b/server/src/html/vote.rs index 3aa00c417c89a9cab3417c650b50ed7c73f08e20..cadbec188b17a48a63b269c0e2fa2ea8ffedd7ed 100644 --- a/server/src/html/vote.rs +++ b/server/src/html/vote.rs @@ -4,11 +4,13 @@ use axum::{ extract::{Query, State}, response::{Html, IntoResponse}, }; +use axum_extra::extract::cookie::CookieJar; use maud::{html, Markup}; use serde::Deserialize; use std::collections::HashSet; use crate::{ + auth::nav_pseudonym, fetch::html::entity_section, form_template::template_json_compact, html::{ranking_panel_with_highlights, scope_theme_style, JsBuilder}, @@ -262,6 +264,7 @@ fn suggest_next( pub async fn vote_page( State(state): State, + jar: CookieJar, Query(q): Query, ) -> impl IntoResponse { let parent = parse_item_param(&q.parent); @@ -329,8 +332,9 @@ pub async fn vote_page( let path = format!("/vote?parent={}", urlencoding::encode(parent.as_str())); state.views.increment(path.clone()); let views = state.views.get_views(&path); + let nav_user = nav_pseudonym(state.projection_store.db(), &jar); - Html(layout(&title, body, views).into_string()).into_response() + Html(layout(&title, body, views, nav_user.as_deref()).into_string()).into_response() } #[cfg(test)] diff --git a/server/static/sorter.css b/server/static/sorter.css index e66a1e6c1acc473c8ff1ddb1e16e75a82d33741c..257280b6b490c65222e580a325b77351cac6cc6b 100644 --- a/server/static/sorter.css +++ b/server/static/sorter.css @@ -34,6 +34,47 @@ body { font-size: 0.75rem; } +.top-nav { + display: flex; + align-items: center; + justify-content: flex-end; + gap: 0.75rem; + padding: 0.5rem 1rem; + font-size: 0.875rem; +} + +.top-nav a { + color: var(--muted); + text-decoration: none; +} + +.top-nav a:hover { + color: var(--fg); +} + +.top-nav-user { + color: var(--fg); + font-weight: 600; +} + +.top-nav-logout { + display: inline; + margin: 0; +} + +.top-nav-logout button { + background: none; + border: none; + padding: 0; + color: var(--muted); + font: inherit; + cursor: pointer; +} + +.top-nav-logout button:hover { + color: var(--fg); +} + .btn-primary { background: var(--accent); color: var(--accent-fg, #0f1115); diff --git a/test/support/harness.clj b/test/support/harness.clj index 3f05951f418258642dcacb4a10ccccc8bfbe8748..4505ece5aa193e826ca61c52f1467d252080d66b 100644 --- a/test/support/harness.clj +++ b/test/support/harness.clj @@ -43,6 +43,7 @@ "SORTER2_VIEWS_LOG" (str data-dir "/views.jsonl") "PORT" (str app-port) "SORTER2_BASE_URL" (str "http://127.0.0.1:" app-port) + "SORTER2_ALLOW_MOCK_OAUTH" "1" "GITHUB_CLIENT_ID" "test-client" "GITHUB_CLIENT_SECRET" "test-secret" "GITHUB_OAUTH_BASE" (str "http://127.0.0.1:" oauth-port) Side B — contributor: tommy-mor Side B — commit message: [bf118bdf] Sanitize Reddit entity body HTML before rendering. Use ammonia at render time so untrusted selftext_html cannot execute scripts in our origin. Co-authored-by: Cursor Side B — unified diff (full patch): diff --git a/Cargo.lock b/Cargo.lock index 3dec7cb72a182dc654a37dca8ba0b49d77504daa..0dd4fce5fb6400ae153cca4e3dbf5a5158e6d8b4 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -11,6 +11,19 @@ dependencies = [ "memchr", ] +[[package]] +name = "ammonia" +version = "4.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "17e913097e1a2124b46746c980134e8c954bc17a6a59bb3fde96f088d126dde6" +dependencies = [ + "cssparser", + "html5ever", + "maplit", + "tendril", + "url", +] + [[package]] name = "anyhow" version = "1.0.102" @@ -355,6 +368,29 @@ version = "0.2.4" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5" +[[package]] +name = "cssparser" +version = "0.35.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4e901edd733a1472f944a45116df3f846f54d37e67e68640ac8bb69689aca2aa" +dependencies = [ + "cssparser-macros", + "dtoa-short", + "itoa", + "phf", + "smallvec", +] + +[[package]] +name = "cssparser-macros" +version = "0.6.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "13b588ba4ac1a99f7f2964d24b3d896ddc6bf847ee3855dbd4366f058cfcd331" +dependencies = [ + "quote", + "syn", +] + [[package]] name = "deranged" version = "0.5.8" @@ -381,6 +417,21 @@ version = "0.15.7" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "1aaf95b3e5c8f23aa320147307562d361db0ae0d51242340f558153b4eb2439b" +[[package]] +name = "dtoa" +version = "1.0.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4c3cf4824e2d5f025c7b531afcb2325364084a16806f6d47fbc1f5fbd9960590" + +[[package]] +name = "dtoa-short" +version = "0.3.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cd1511a7b6a56299bd043a9c167a6d2bfb37bf84a6dfceaba651168adfb43c87" +dependencies = [ + "dtoa", +] + [[package]] name = "durable" version = "0.2.0" @@ -482,6 +533,16 @@ dependencies = [ "percent-encoding", ] +[[package]] +name = "futf" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "df420e2e84819663797d1ec6544b13c5be84629e7bb00dc960d6917db2987843" +dependencies = [ + "mac", + "new_debug_unreachable", +] + [[package]] name = "futures-channel" version = "0.3.32" @@ -614,6 +675,17 @@ version = "0.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea" +[[package]] +name = "html5ever" +version = "0.35.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "55d958c2f74b664487a2035fe1dadb032c48718a03b63f3ab0b8537db8549ed4" +dependencies = [ + "log", + "markup5ever", + "match_token", +] + [[package]] name = "http" version = "1.4.1" @@ -974,6 +1046,15 @@ version = "0.8.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0" +[[package]] +name = "lock_api" +version = "0.4.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "224399e74b87b5f3557511d98dff8b14089b3dadafcab6bb93eab67d3aace965" +dependencies = [ + "scopeguard", +] + [[package]] name = "log" version = "0.4.30" @@ -990,6 +1071,40 @@ dependencies = [ "libc", ] +[[package]] +name = "mac" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c41e0c4fef86961ac6d6f8a82609f55f31b05e4fce149ac5710e439df7619ba4" + +[[package]] +name = "maplit" +version = "1.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3e2e65a1a2e43cfcb47a895c4c8b10d1f4a61097f9f254f183aee60cad9c651d" + +[[package]] +name = "markup5ever" +version = "0.35.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "311fe69c934650f8f19652b3946075f0fc41ad8757dbb68f1ca14e7900ecc1c3" +dependencies = [ + "log", + "tendril", + "web_atoms", +] + +[[package]] +name = "match_token" +version = "0.35.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac84fd3f360fcc43dc5f5d186f02a94192761a080e8bc58621ad4d12296a58cf" +dependencies = [ + "proc-macro2", + "quote", + "syn", +] + [[package]] name = "matchers" version = "0.2.0" @@ -1092,6 +1207,12 @@ dependencies = [ "tempfile", ] +[[package]] +name = "new_debug_unreachable" +version = "1.0.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "650eef8c711430f1a879fdd01d4745a7deea475becfb90269c06775983bbf086" + [[package]] name = "nom" version = "7.1.3" @@ -1175,6 +1296,29 @@ dependencies = [ "vcpkg", ] +[[package]] +name = "parking_lot" +version = "0.12.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "93857453250e3077bd71ff98b6a65ea6621a19bb0f559a85248955ac12c45a1a" +dependencies = [ + "lock_api", + "parking_lot_core", +] + +[[package]] +name = "parking_lot_core" +version = "0.9.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1" +dependencies = [ + "cfg-if", + "libc", + "redox_syscall", + "smallvec", + "windows-link", +] + [[package]] name = "peeking_take_while" version = "0.1.2" @@ -1187,6 +1331,58 @@ version = "2.3.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220" +[[package]] +name = "phf" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fd6780a80ae0c52cc120a26a1a42c1ae51b247a253e4e06113d23d2c2edd078" +dependencies = [ + "phf_macros", + "phf_shared", +] + +[[package]] +name = "phf_codegen" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "aef8048c789fa5e851558d709946d6d79a8ff88c0440c587967f8e94bfb1216a" +dependencies = [ + "phf_generator", + "phf_shared", +] + +[[package]] +name = "phf_generator" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3c80231409c20246a13fddb31776fb942c38553c51e871f8cbd687a4cfb5843d" +dependencies = [ + "phf_shared", + "rand 0.8.6", +] + +[[package]] +name = "phf_macros" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f84ac04429c13a7ff43785d75ad27569f2951ce0ffd30a3321230db2fc727216" +dependencies = [ + "phf_generator", + "phf_shared", + "proc-macro2", + "quote", + "syn", +] + +[[package]] +name = "phf_shared" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "67eabc2ef2a60eb7faa00097bd1ffdb5bd28e62bf39990626a582201b7a754e5" +dependencies = [ + "siphasher", +] + [[package]] name = "pin-project-lite" version = "0.2.17" @@ -1223,6 +1419,12 @@ dependencies = [ "zerocopy", ] +[[package]] +name = "precomputed-hash" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "925383efa346730478fb4838dbe9137d2a47675ad789c546d150a6e1dd4ab31c" + [[package]] name = "prettyplease" version = "0.2.37" @@ -1379,6 +1581,15 @@ dependencies = [ "rand_core 0.9.5", ] +[[package]] +name = "redox_syscall" +version = "0.5.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed2bf2547551a7053d6fdfafda3f938979645c44812fbfcda098faae3f1a362d" +dependencies = [ + "bitflags 2.11.1", +] + [[package]] name = "regex" version = "1.12.3" @@ -1563,6 +1774,12 @@ dependencies = [ "windows-sys 0.61.2", ] +[[package]] +name = "scopeguard" +version = "1.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49" + [[package]] name = "security-framework" version = "3.7.0" @@ -1683,6 +1900,12 @@ dependencies = [ "libc", ] +[[package]] +name = "siphasher" +version = "1.0.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8ee5873ec9cce0195efcb7a4e9507a04cd49aec9c83d0389df45b1ef7ba2e649" + [[package]] name = "slab" version = "0.4.12" @@ -1709,6 +1932,7 @@ dependencies = [ name = "sorter2-server" version = "0.0.1" dependencies = [ + "ammonia", "async-stream", "axum", "axum-extra", @@ -1742,6 +1966,31 @@ version = "1.2.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" +[[package]] +name = "string_cache" +version = "0.8.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bf776ba3fa74f83bf4b63c3dcbbf82173db2632ed8452cb2d891d33f459de70f" +dependencies = [ + "new_debug_unreachable", + "parking_lot", + "phf_shared", + "precomputed-hash", + "serde", +] + +[[package]] +name = "string_cache_codegen" +version = "0.5.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c711928715f1fe0fe509c53b43e993a9a557babc2d0a3567d0a3006f1ac931a0" +dependencies = [ + "phf_generator", + "phf_shared", + "proc-macro2", + "quote", +] + [[package]] name = "subtle" version = "2.6.1" @@ -1813,6 +2062,17 @@ dependencies = [ "windows-sys 0.61.2", ] +[[package]] +name = "tendril" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d24a120c5fc464a3458240ee02c299ebcb9d67b5249c8848b09d639dca8d7bb0" +dependencies = [ + "futf", + "mac", + "utf-8", +] + [[package]] name = "thiserror" version = "1.0.69" @@ -2116,6 +2376,12 @@ version = "2.1.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da" +[[package]] +name = "utf-8" +version = "0.7.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "09cc8ee72d2a9becf2f2febe0205bbed8fc6615b7cb429ad062dc7b7ddd036a9" + [[package]] name = "utf8_iter" version = "1.0.4" @@ -2281,6 +2547,18 @@ dependencies = [ "wasm-bindgen", ] +[[package]] +name = "web_atoms" +version = "0.1.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "57ffde1dc01240bdf9992e3205668b235e59421fd085e8a317ed98da0178d414" +dependencies = [ + "phf", + "phf_codegen", + "string_cache", + "string_cache_codegen", +] + [[package]] name = "windows-link" version = "0.2.1" diff --git a/server/Cargo.toml b/server/Cargo.toml index 47659ff82fbfb50972eb2b87575e80f66e572ba4..27f552c20b97ef28cdde4cb6b1a4980375135111 100644 --- a/server/Cargo.toml +++ b/server/Cargo.toml @@ -13,6 +13,7 @@ serde = { version = "1", features = ["derive"] } serde_json = "1" thiserror = "1" maud = { version = "0.26", features = ["axum"] } +ammonia = "4.1" tower = "0.5" tower-http = { version = "0.5", features = ["trace"] } tracing = "0.1" diff --git a/server/src/fetch/html.rs b/server/src/fetch/html.rs index dadf050515f0473943dad97df5d318032c8cb385..5b160c6b8bd216dfaf80149854aec0566cd00460 100644 --- a/server/src/fetch/html.rs +++ b/server/src/fetch/html.rs @@ -4,6 +4,7 @@ use maud::{html, Markup}; use crate::{ form_template::template_json_compact, + html::sanitize::entity_body_html, path_types::ItemId, reddit::{is_children_fetchable, is_fetchable}, reducer::NodeState, @@ -27,7 +28,7 @@ pub fn entity_panel(node: &NodeState) -> Markup { p class="muted small" { "by " (author) } } @if let Some(body) = &data.body_html { - div class="entity-body" { (maud::PreEscaped(body)) } + div class="entity-body" { (maud::PreEscaped(entity_body_html(body))) } } } } diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs index e180a0ca542a33e2300c0a4809e6b9cfee07ecfe..a58cbbee3490a08a625cb06df06848c59a615d65 100644 --- a/server/src/html/mod.rs +++ b/server/src/html/mod.rs @@ -20,6 +20,7 @@ use crate::{ ui_action::UI_RPC_FIELD, }; +pub mod sanitize; pub mod vote; const SORTER_CSS: &str = include_str!("../../static/sorter.css"); diff --git a/server/src/html/sanitize.rs b/server/src/html/sanitize.rs new file mode 100644 index 0000000000000000000000000000000000000000..6685ed2535281b9fd5d65b042cbc5a11c5d4df37 --- /dev/null +++ b/server/src/html/sanitize.rs @@ -0,0 +1,39 @@ +//! Whitelist sanitization for untrusted HTML fragments (e.g. Reddit `selftext_html`). + +use std::sync::LazyLock; + +use ammonia::Builder; + +static ENTITY_BODY: LazyLock> = LazyLock::new(|| { + let mut b = Builder::default(); + b.strip_comments(true); + b.link_rel(Some("noopener noreferrer")); + b +}); + +/// Sanitize HTML safe for embedding in our pages via [`maud::PreEscaped`]. +pub fn entity_body_html(raw: &str) -> String { + ENTITY_BODY.clean(raw).to_string() +} + +#[cfg(test)] +mod tests { + use super::entity_body_html; + + #[test] + fn keeps_benign_markup() { + assert_eq!( + entity_body_html("

release notes

"), + "

release notes

" + ); + } + + #[test] + fn strips_scripts_and_event_handlers() { + let raw = "

ok

"; + let clean = entity_body_html(raw); + assert!(!clean.contains("ok

")); + } +} diff --git a/server/src/render/reddit.rs b/server/src/render/reddit.rs index c4f98fc760c32ce1b41a91bd41e97908bd198937..7f840aa33b734a31d8cf3341a0581c8bcb9bbcf3 100644 --- a/server/src/render/reddit.rs +++ b/server/src/render/reddit.rs @@ -3,6 +3,7 @@ use maud::{html, Markup}; use crate::{ + html::sanitize::entity_body_html, path_types::ItemId, reducer::{EntityData, GlobalTree, NodeState}, }; @@ -57,7 +58,7 @@ fn post_entity_card(data: &EntityData) -> Markup { } } @if let Some(body) = &data.body_html { - div class="entity-body" { (maud::PreEscaped(body)) } + div class="entity-body" { (maud::PreEscaped(entity_body_html(body))) } } } }