From 117012423f311487f2e83d45f875cd8a893645d5 Mon Sep 17 00:00:00 2001 From: Philip Pfaffe Date: Mon, 3 Jul 2023 16:43:26 +0000 Subject: [PATCH] Sanitize resultsdb summary html a bit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This will prevent error messages with html tags in them from accidentally formatting the error message Bug: none Change-Id: Iea6f1e84017dfc4451fe6aad331abf2d1a1c2133 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4660497 Reviewed-by: Liviu Rau Commit-Queue: Liviu Rau Reviewed-by: Simon Zünd Auto-Submit: Philip Pfaffe --- test/shared/mocha-resultsdb-reporter.ts | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/test/shared/mocha-resultsdb-reporter.ts b/test/shared/mocha-resultsdb-reporter.ts index e48cccdaec..b292a1353c 100644 --- a/test/shared/mocha-resultsdb-reporter.ts +++ b/test/shared/mocha-resultsdb-reporter.ts @@ -13,7 +13,15 @@ const { EVENT_TEST_PENDING, } = Mocha.Runner.constants; -function getErrorMessage(error: Error|unknown) { +function sanitize(message: string): string { + return message.replaceAll('&', '&') + .replaceAll('<', '<') + .replaceAll('>', '>') + .replaceAll('"', '"') + .replaceAll('\'', '''); +} + +function getErrorMessage(error: Error|unknown): string { if (error instanceof Error) { if (error.cause) { // TypeScript types error.cause as {}, which doesn't allow us to access @@ -21,11 +29,11 @@ function getErrorMessage(error: Error|unknown) { // to read the `message` property. const cause = error.cause as {message?: string}; const causeMessage = cause.message || ''; - return `${error.message}\n${causeMessage}`; + return sanitize(`${error.message}\n${causeMessage}`); } - return error.stack; + return sanitize(error.stack ?? error.message); } - return `${error}`; + return sanitize(`${error}`); } class ResultsDbReporter extends Mocha.reporters.Spec {