From ea79d52f72c91075067d9fb6944b6be3e3f3dba6 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 11 Aug 2026 12:33:21 +0000 Subject: [PATCH] Escape DSAR request fields in the staff HTML email (OY-07) buildDsarEmailHtml interpolated user.id, username, email, requestType, jurisdiction, and the user-controlled details/jurisdiction fields straight into an HTML email sent to contact@oyme.site. A requester could inject arbitrary markup (link/section spoofing, phishing) into mail that staff read. Add an escapeHtml helper (& first, then < > " ') and wrap every interpolated value. - worker/routes/dsar.ts: escapeHtml helper; every ${...} in buildDsarEmailHtml wrapped, user.id coerced via String(). - tests/worker/dsar.test.ts: submit details/jurisdiction containing ", + }, + }); + + assert.equal(res.status, 200); + assert.equal(json.success, true); + assert.ok(emailPayload); + const html = String(emailPayload?.html); + // Escaped forms are present. + assert.ok(html.includes("<script>alert(1)</script>")); + assert.ok(html.includes("<img src=x onerror=alert(1)>")); + // Raw markup is not. + assert.ok(!html.includes("