Description
Certain HTML/JavaScript bypasses the Bleach sanitization in CKEditor post content, allowing potential XSS attacks.
Steps to Reproduce
- Create a post with the following content:
html <img src=x onerror=alert('XSS')>
- The content is saved and rendered without sanitization
- The script executes when other users view the post
Expected Behavior
All dangerous HTML/JavaScript should be stripped by Bleach before saving. Only safe formatting tags should be allowed.
Root Cause
The CKEditor output contains HTML that bypasses the Bleach whitelist. Some event handler attributes and dangerous tags are not filtered.
Files to Fix
- linkup/feed/views.py - Enhance Bleach sanitization with stricter whitelist
- linkup/feed/models.py - Add clean() method to Post model
- linkup/core/validators.py - Add HTML content validator
- Test with OWASP XSS Prevention Cheat Sheet payloads
Acceptance Criteria
Description
Certain HTML/JavaScript bypasses the Bleach sanitization in CKEditor post content, allowing potential XSS attacks.
Steps to Reproduce
html <img src=x onerror=alert('XSS')>Expected Behavior
All dangerous HTML/JavaScript should be stripped by Bleach before saving. Only safe formatting tags should be allowed.
Root Cause
The CKEditor output contains HTML that bypasses the Bleach whitelist. Some event handler attributes and dangerous tags are not filtered.
Files to Fix
Acceptance Criteria