Commit 40eb6e7
authored
PLU-559: HTML injection via pipe name to blacklist emails (#1204)
## Problem
Plumber sends error emails via Postman when a recipient is blacklisted.
In these emails, the pipe title is directly interpolated into the HTML
body without sanitisation. This means if the pipe name includes HTML
tags, they will be embedded into the email.
This is not really a major issue since Postman sanitises the input
before sending the email.
## Solution
1. Sanitise the pipe name using `DOMPurify`
2. Escape the HTML so we display the Pipe name as-is if the user insists
on having HTML tags in their pipe names.
## Screenshots
<img width="368" height="94" alt="Screenshot 2025-09-10 at 6 02 00 PM"
src="https://github.com/user-attachments/assets/a14ee99f-ac1b-40e6-a447-a6f45a0a4513"
/>
<img width="1117" height="173" alt="Screenshot 2025-09-10 at 6 04 21 PM"
src="https://github.com/user-attachments/assets/24fb5d70-90f1-422f-a829-f92a0f81b8f2"
/>
<img width="250" height="72" alt="Screenshot 2025-09-10 at 6 05 20 PM"
src="https://github.com/user-attachments/assets/fbcc7562-35b1-4aa3-97f2-82829bfb9087"
/>
<img width="1122" height="174" alt="Screenshot 2025-09-10 at 6 05 10 PM"
src="https://github.com/user-attachments/assets/6ecf7597-bb01-46a6-b6c3-a09694e76ef6"
/>
## Tests
- [ ] Normal pipe names (without HTML tags) are sent correctly for
blacklisted emails
- [ ] Pipe names with dangerous HTML tags are sanitised
- [ ] Pipe names with normal HTML tags are displayed as-is1 parent 93161e8 commit 40eb6e7
File tree
5 files changed
+100
-3
lines changed- packages/backend/src
- apps/postman/common
- helpers
- __tests__
5 files changed
+100
-3
lines changedLines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
51 | 52 | | |
52 | 53 | | |
53 | 54 | | |
54 | | - | |
| 55 | + | |
55 | 56 | | |
56 | 57 | | |
57 | 58 | | |
| |||
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
| 2 | + | |
2 | 3 | | |
3 | 4 | | |
4 | 5 | | |
| |||
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
22 | | - | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
Lines changed: 66 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
8 | 10 | | |
9 | 11 | | |
10 | 12 | | |
| |||
26 | 28 | | |
27 | 29 | | |
28 | 30 | | |
29 | | - | |
| 31 | + | |
30 | 32 | | |
31 | 33 | | |
32 | 34 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
0 commit comments