From 4244df93dee5c7bad8bc15a230cdbac420b27bfb Mon Sep 17 00:00:00 2001 From: "reed%reedloden.com" Date: Tue, 1 Jul 2008 06:07:38 +0000 Subject: [PATCH] Bug 441169 - [p=johnath@mozilla.com (Johnathan Nightingale [johnath]) r=bzbarsky sr=dveditz a=beltzner] git-svn-id: svn://10.0.0.236/trunk@252727 18797224-902f-48f8-a5cc-f745e15eee43 --- .../docshell/resources/content/netError.xhtml | 30 +++++++++++++++++-- mozilla/docshell/test/browser/Makefile.in | 1 + .../test/browser/browser_bug441169.js | 26 ++++++++++++++++ 3 files changed, 55 insertions(+), 2 deletions(-) create mode 100644 mozilla/docshell/test/browser/browser_bug441169.js diff --git a/mozilla/docshell/resources/content/netError.xhtml b/mozilla/docshell/resources/content/netError.xhtml index 7409ed47b6a..5d59289d0e0 100644 --- a/mozilla/docshell/resources/content/netError.xhtml +++ b/mozilla/docshell/resources/content/netError.xhtml @@ -214,8 +214,34 @@ function addDomainErrorLink() { // Rather than textContent, we need to treat description as HTML var sd = document.getElementById("errorShortDescText"); - if (sd) - sd.innerHTML = getDescription(); + if (sd) { + var desc = getDescription(); + + // sanitize description text - see bug 441169 + + // First, find the index of the tag we care about, being careful not to + // use an over-greedy regex + var re = //; + var result = re.exec(desc); + if(!result) + return; + + // Remove sd's existing children + sd.textContent = ""; + + // Everything up to the link should be text content + sd.appendChild(document.createTextNode(desc.slice(0, result.index))); + + // Now create the link itself + var anchorEl = document.createElement("a"); + anchorEl.setAttribute("id", "cert_domain_link"); + anchorEl.setAttribute("title", result[1]); + anchorEl.appendChild(document.createTextNode(result[1])); + sd.appendChild(anchorEl); + + // Finally, append text for anything after the closing + sd.appendChild(document.createTextNode(desc.slice(desc.indexOf("") + "".length))); + } var link = document.getElementById('cert_domain_link'); if (!link) diff --git a/mozilla/docshell/test/browser/Makefile.in b/mozilla/docshell/test/browser/Makefile.in index 06ddbc21619..120614a6554 100644 --- a/mozilla/docshell/test/browser/Makefile.in +++ b/mozilla/docshell/test/browser/Makefile.in @@ -47,6 +47,7 @@ _BROWSER_TEST_FILES = \ browser_bug349769.js \ browser_bug388121-1.js \ browser_bug388121-2.js \ + browser_bug441169.js \ $(NULL) # the tests below use FUEL, which is a Firefox-specific feature diff --git a/mozilla/docshell/test/browser/browser_bug441169.js b/mozilla/docshell/test/browser/browser_bug441169.js new file mode 100644 index 00000000000..6a7be2b7659 --- /dev/null +++ b/mozilla/docshell/test/browser/browser_bug441169.js @@ -0,0 +1,26 @@ +/* Make sure that netError won't allow HTML injection through badcert parameters. See bug 441169. */ +var newBrowser + +// An edited version of the standard neterror url which attempts to +// insert a tag into the text. We will navigate to this page +// and ensure that the span tag is not parsed as HTML. +var chromeURL = "about:neterror?e=nssBadCert&u=https%3A//test.kuix.de/&c=UTF-8&d=This%20sentence%20should%20not%20be%20parsed%20to%20include%20a%20%3Cspan%20id=%22test_span%22%3Enamed%3C/span%3E%20span%20tag.%0A%0AThe%20certificate%20is%20only%20valid%20for%20%3Ca%20id=%22cert_domain_link%22%20title=%22kuix.de%22%3Ekuix.de%3C/a%3E%0A%0A(Error%20code%3A%20ssl_error_bad_cert_domain)"; + +function test() { + waitForExplicitFinish(); + + var newTab = gBrowser.addTab(); + gBrowser.selectedTab = newTab; + newBrowser = gBrowser.getBrowserForTab(newTab); + + window.addEventListener("DOMContentLoaded", checkPage, false); + newBrowser.contentWindow.location = chromeURL; +} + +function checkPage() { + + is(newBrowser.contentDocument.getElementById("test_span"), null, "Error message should not be parsed as HTML, and hence shouldn't include the 'test_span' element."); + + gBrowser.removeCurrentTab(); + finish(); +}