Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / assets / solaris-11.svg
Author[]Andy Green <andy@warmcat.com> 2026-09-06 07:40 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-09-06 07:40 UTC
Tree419ef5dc908b4cf5bcec16bf6eed1458facccc69   Raw Patch
 
web: JSON-escape alang in builders message header, fixes F-005
web: JSON-escape alang in builders message header, fixes F-005

The com.warmcat.sai.builders header interpolated pss->alang (the
browser-controlled Accept-Language header captured at the ws upgrade)
after lws_sql_purify(), which only doubles single quotes and passes
double quotes, braces and backslashes through untouched -- so an
Accept-Language value like x"}INJECTED could add attacker-chosen JSON
structure to the message the browser parses.  The overview path already
escapes the same field correctly with lws_json_purify(); use it here
too.
diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index fdcc16b..0941c6b 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -2067,7 +2067,8 @@ saiw_browser_broadcast_queue_builders(struct vhd *vhd, struct pss *pss) "{\"schema\":\"com.warmcat.sai.builders\"," " \"alang\":\"%s\"," " \"builders\":[", - lws_sql_purify(esc, pss->alang, sizeof(esc) - 1)); + lws_json_purify(esc, pss->alang, sizeof(esc) - 1, + NULL)); if (sai_dyn_buf_append(&d, buf, (size_t)n)) { free(d.buf); return 1;
Page fetched 0s ago, creation time: 9ms (vhost etag hits: 0%, cache hits: 0%)