Files
notifications-admin/app/templates/views/service-settings/letter-contact-details.html
Leo Hemsted 5bbbdc3cd9 fix xss with service letter contact blocks
service contact blocks contain new lines - and jinja2 normally ignores
newlines (as in it keeps them as new lines) - but we need to turn them
into `<br>` tags so that we can show the formatting that the user has
added. We were previously just doing `{{ block | nl2br | safe }}`. nl2br
turns the new lines into `<br>` tags, and then `safe` tells jinja that
it doesn't need to escape the html.

this causes issues if the user adds `<script>alert(1)</script>` to their
contact block (or some other evil xss hack), where that will get let
through due to the safe flag

To solve this, use `Markup(html='escape')` to sanitise any html, and
then convert new lines to <br>.

bump utils

another xss
2020-01-21 17:34:49 +00:00

61 lines
2.1 KiB
HTML

{% extends "withnav_template.html" %}
{% from "components/api-key.html" import api_key %}
{% from "components/page-header.html" import page_header %}
{% from "components/page-footer.html" import page_footer %}
{% from "components/table.html" import row_group, row, text_field, edit_field, field, boolean_field, list_table with context %}
{% block service_page_title %}
Sender addresses
{% endblock %}
{% block maincolumn_content %}
<div class="bottom-gutter">
{{ page_header(
'Sender addresses',
back_link=url_for('main.service_settings', service_id=current_service.id)
) }}
</div>
<div class="user-list">
<div class="user-list-item">
<span class="hint">
Blank
{% if current_service.default_letter_contact_block %}
{% if current_user.has_permissions('manage_service') %}
<a class="user-list-edit-link" href="{{ url_for('.service_make_blank_default_letter_contact', service_id =current_service.id) }}">Make default</a>
{% endif %}
{% else %}
(default)
{% endif %}
</span>
</div>
{% for item in letter_contact_details %}
<div class="user-list-item">
<p>
{{ item.contact_block | nl2br }}
</p>
<p class="hint">
{%- if item.is_default -%}
(default)
{% endif %}
</p>
{% if current_user.has_permissions('manage_service') %}
<a class="user-list-edit-link" href="{{ url_for('.service_edit_letter_contact', service_id =current_service.id, letter_contact_id = item.id) }}">Change</a>
{% endif %}
{% if letter_contact_details|length > 1 %}
{{ api_key(item.id, thing="ID") }}
{% endif %}
</div>
{% endfor %}
</div>
{% if current_user.has_permissions('manage_service') %}
<div class="grid-row">
<div class="column-whole">
<div class="js-stick-at-bottom-when-scrolling">
<a href="{{ url_for('.service_add_letter_contact', service_id=current_service.id) }}" class="button">Add a new address</a>
</div>
</div>
</div>
{% endif %}
{% endblock %}