Module: Loofah::HTML5::Scrub

Defined in:
lib/loofah/html5/scrub.rb

Constant Summary collapse

CONTROL_CHARACTERS =
/[`\u0000-\u0020\u007f\u0080-\u0101]/
CSS_KEYWORDISH =

rubocop:disable Layout/LineLength

/\A(#[0-9a-fA-F]+|rgb\(\d+%?,\d*%?,?\d*%?\)?|-?\d{0,3}\.?\d{0,10}(ch|cm|r?em|ex|in|lh|mm|pc|pt|px|Q|vmax|vmin|vw|vh|%|,|\))?)\z/
CRASS_SEMICOLON =
{ node: :semicolon, raw: ";" }
CSS_IMPORTANT =
"!important"
CSS_WHITESPACE =
" "
CSS_PROPERTY_STRING_WITHOUT_EMBEDDED_QUOTES =
/\A(["'])?[^"']+\1\z/
DATA_ATTRIBUTE_NAME =
/\Adata-[\w-]+\z/
NUMERIC_CHARACTER_REFERENCE =

Decimal (&#58) or hexadecimal (&#x3a) form, with or without the trailing semicolon that CGI.unescapeHTML requires but browsers do not.

/&#(x[0-9a-f]+|[0-9]+);?/i
URI_PROTOCOL_REGEX =

A scheme (RFC 3986) followed by a protocol separator. The separator must recognize the same encoded-colon forms as PROTOCOL_SEPARATOR, otherwise a scheme split by an encoded colon (for example "javascript&#58alert(1)") would not be recognized as having a scheme and would skip protocol validation.

/\A[a-z][a-z0-9+\-.]*#{SafeList::PROTOCOL_SEPARATOR}/
DATA_URI_MEDIATYPE =

Matches a valid MIME type "essence" (type "/" subtype, no parameters), used to decide whether a data: URI mediatype is well-formed; a non-match is not a valid MIME type, which the data: URL processor treats as text/plain. Specs:

https://mimesniff.spec.whatwg.org/#valid-mime-type
https://mimesniff.spec.whatwg.org/#mime-type-essence
https://mimesniff.spec.whatwg.org/#http-token-code-point

The character class below is the HTTP token set (tchar) from RFC 9110 section 5.6.2, https://www.rfc-editor.org/rfc/rfc9110#name-tokens :

tchar = "!" / "#" / "$" / "%" / "&" / "'" / "*" / "+" / "-" / "." / "^"
    / "_" / "`" / "|" / "~" / DIGIT / ALPHA

ALPHA is written a-z, not a-zA-Z, because allowed_uri? downcases the input first.

%r{
  \A
  [a-z0-9!\#$%&'*+\-.^_`|~]+   # type:    1*tchar
  /                            # "/" is not a tchar, so it is the sole delimiter
  [a-z0-9!\#$%&'*+\-.^_`|~]+   # subtype: 1*tchar
  \z
}x
WHITESPACE_CHARACTER_REFERENCES =

HTML5 named character references for whitespace that browsers strip from URIs. CGI.unescapeHTML does not decode these, so they are handled explicitly.

/&(Tab|NewLine);/
TABLE_FOR_ESCAPE_HTML__ =
{
  "<" => "&lt;",
  ">" => "&gt;",
  "&" => "&amp;",
}

Class Method Summary collapse

Class Method Details

.allowed_element?(element_name) ⇒ Boolean

Returns:

  • (Boolean)


56
57
58
# File 'lib/loofah/html5/scrub.rb', line 56

def allowed_element?(element_name)
  ::Loofah::HTML5::SafeList::ALLOWED_ELEMENTS_WITH_LIBXML2.include?(element_name)
end

.allowed_uri?(uri_string) ⇒ Boolean

Returns true if the given URI string is safe, false otherwise. This method can be used to validate URI attribute values without requiring a Nokogiri DOM node.

Returns:

  • (Boolean)


182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
# File 'lib/loofah/html5/scrub.rb', line 182

def allowed_uri?(uri_string)
  # CGI.unescapeHTML decodes numeric references only when they carry a trailing semicolon, so
  # also decode the semicolon-less ones, which browsers still decode and execute. Normalizing
  # more aggressively than a browser only rejects more, which is safe. Control characters are
  # stripped both before and after decoding, since decoding can produce them. That strip must
  # precede WHITESPACE_CHARACTER_REFERENCES: removing a control character can reveal a named
  # whitespace reference.
  uri_string = decode_numeric_character_references(CGI.unescapeHTML(uri_string.gsub(CONTROL_CHARACTERS, "")))
  uri_string.gsub!(CONTROL_CHARACTERS, "")
  uri_string.gsub!(WHITESPACE_CHARACTER_REFERENCES, "")
  uri_string.gsub!("&colon;", ":")
  uri_string.downcase!
  if URI_PROTOCOL_REGEX.match?(uri_string)
    protocol = uri_string.split(SafeList::PROTOCOL_SEPARATOR)[0]
    return false unless SafeList::ALLOWED_PROTOCOLS.include?(protocol)

    if protocol == "data"
      # permit only allowed data mediatypes
      return false unless SafeList::ALLOWED_URI_DATA_MEDIATYPES.include?(data_uri_mediatype(uri_string))
    end
  end
  true
end

.cdata_escape(node) ⇒ Object



266
267
268
269
270
271
272
273
# File 'lib/loofah/html5/scrub.rb', line 266

def cdata_escape(node)
  escaped_text = escape_tags(node.text)
  if Nokogiri.jruby?
    node.document.create_text_node(escaped_text)
  else
    node.document.create_cdata(escaped_text)
  end
end

.cdata_needs_escaping?(node) ⇒ Boolean

Returns:

  • (Boolean)


261
262
263
264
# File 'lib/loofah/html5/scrub.rb', line 261

def cdata_needs_escaping?(node)
  # Nokogiri's HTML4 parser on JRuby doesn't flag the child of a `style` tag as cdata, but it acts that way
  node.cdata? || (Nokogiri.jruby? && node.text? && node.parent.name == "style")
end

.decode_numeric_character_references(string) ⇒ Object



206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
# File 'lib/loofah/html5/scrub.rb', line 206

def decode_numeric_character_references(string)
  string.gsub(NUMERIC_CHARACTER_REFERENCE) do |reference|
    digits = ::Regexp.last_match(1)
    hexadecimal = digits.start_with?("x", "X")
    digits = digits[1..-1] if hexadecimal
    significant_digits = digits.sub(/\A0+/, "")

    # The largest code point is U+10FFFF: 7 decimal or 6 hexadecimal significant digits.
    # Anything longer is out of range; skip it without building a large integer from it.
    next reference if significant_digits.length > (hexadecimal ? 6 : 7)

    codepoint = significant_digits.to_i(hexadecimal ? 16 : 10)
    begin
      codepoint.chr(Encoding::UTF_8)
    rescue RangeError
      reference
    end
  end
end

.escape_tags(string) ⇒ Object



281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
# File 'lib/loofah/html5/scrub.rb', line 281

def escape_tags(string)
  # modified version of CGI.escapeHTML from ruby 3.1
  enc = string.encoding
  if enc.ascii_compatible?
    string = string.b
    string.gsub!(/[<>&]/, TABLE_FOR_ESCAPE_HTML__)
    string.force_encoding(enc)
  else
    if enc.dummy?
      origenc = enc
      enc = Encoding::Converter.asciicompat_encoding(enc)
      string = enc ? string.encode(enc) : string.b
    end
    table = Hash[TABLE_FOR_ESCAPE_HTML__.map { |pair| pair.map { |s| s.encode(enc) } }]
    string = string.gsub(/#{"[<>&]".encode(enc)}/, table)
    string.encode!(origenc) if origenc
    string
  end
end

.force_correct_attribute_escaping!(node) ⇒ Object

libxml2 >= 2.9.2 fails to escape comments within some attributes.

see comments about CVE-2018-8048 within the tests for more information



240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
# File 'lib/loofah/html5/scrub.rb', line 240

def force_correct_attribute_escaping!(node)
  return unless Nokogiri::VersionInfo.instance.libxml2?

  node.attribute_nodes.each do |attr_node|
    next unless LibxmlWorkarounds::BROKEN_ESCAPING_ATTRIBUTES.include?(attr_node.name)

    tag_name = LibxmlWorkarounds::BROKEN_ESCAPING_ATTRIBUTES_QUALIFYING_TAG[attr_node.name]
    next unless tag_name.nil? || tag_name == node.name

    #
    #  this block is just like CGI.escape in Ruby 2.4, but
    #  only encodes space and double-quote, to mimic
    #  pre-2.9.2 behavior
    #
    encoding = attr_node.value.encoding
    attr_node.value = attr_node.value.gsub(/[ "]/) do |m|
      "%" + m.unpack("H2" * m.bytesize).join("%").upcase
    end.force_encoding(encoding)
  end
end

.scrub_attribute_that_allows_local_ref(attr_node) ⇒ Object



161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
# File 'lib/loofah/html5/scrub.rb', line 161

def scrub_attribute_that_allows_local_ref(attr_node)
  return unless attr_node.value

  nodes = Crass::Parser.new(attr_node.value).parse_component_values

  values = nodes.map do |node|
    case node[:node]
    when :url
      if node[:value].start_with?("#")
        node[:raw]
      end
    when :hash, :ident, :string
      node[:raw]
    end
  end.compact

  attr_node.value = values.join(" ")
end

.scrub_attributes(node) ⇒ Object

alternative implementation of the html5lib attribute scrubbing algorithm



61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
# File 'lib/loofah/html5/scrub.rb', line 61

def scrub_attributes(node)
  node.attribute_nodes.each do |attr_node|
    attr_name = if attr_node.namespace
      "#{attr_node.namespace.prefix}:#{attr_node.node_name}"
    else
      attr_node.node_name
    end

    if DATA_ATTRIBUTE_NAME.match?(attr_name)
      next
    end

    unless SafeList::ALLOWED_ATTRIBUTES.include?(attr_name)
      attr_node.remove
      next
    end

    if SafeList::ATTR_VAL_IS_URI.include?(attr_name)
      next if scrub_uri_attribute(attr_node)
    end

    if SafeList::SVG_ATTR_VAL_ALLOWS_REF.include?(attr_name)
      scrub_attribute_that_allows_local_ref(attr_node)
    end

    next unless SafeList::SVG_ALLOW_LOCAL_HREF.include?(node.name) &&
      SafeList::SVG_HREF_ATTRIBUTES.include?(attr_name) &&
      attr_node.value =~ /^\s*[^#\s].*/m

    attr_node.remove
    next
  end

  scrub_css_attribute(node)

  node.attribute_nodes.each do |attr_node|
    if attr_node.value !~ /[^[:space:]]/ && attr_node.name !~ DATA_ATTRIBUTE_NAME
      node.remove_attribute(attr_node.name)
    end
  end

  force_correct_attribute_escaping!(node)
end

.scrub_css(style) ⇒ Object



110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
# File 'lib/loofah/html5/scrub.rb', line 110

def scrub_css(style)
  url_flags = [:url, :bad_url]
  style_tree = Crass.parse_properties(style)
  sanitized_tree = []

  style_tree.each do |node|
    next unless node[:node] == :property
    next if node[:children].any? do |child|
      url_flags.include?(child[:node])
    end

    name = node[:name].downcase
    next unless SafeList::ALLOWED_CSS_PROPERTIES.include?(name) ||
      SafeList::ALLOWED_SVG_PROPERTIES.include?(name) ||
      SafeList::SHORTHAND_CSS_PROPERTIES.include?(name.split("-").first)

    value = node[:children].map do |child|
      case child[:node]
      when :whitespace
        CSS_WHITESPACE
      when :string
        if CSS_PROPERTY_STRING_WITHOUT_EMBEDDED_QUOTES.match?(child[:raw])
          Crass::Parser.stringify(child)
        end
      when :function
        if SafeList::ALLOWED_CSS_FUNCTIONS.include?(child[:name].downcase)
          Crass::Parser.stringify(child)
        end
      when :ident
        keyword = child[:value]
        if !SafeList::SHORTHAND_CSS_PROPERTIES.include?(name.split("-").first) ||
            SafeList::ALLOWED_CSS_KEYWORDS.include?(keyword) ||
            (keyword =~ CSS_KEYWORDISH)
          keyword
        end
      else
        child[:raw]
      end
    end.compact.join.strip

    next if value.empty?

    value << CSS_WHITESPACE << CSS_IMPORTANT if node[:important]
    propstring = format("%s:%s", name, value)
    sanitized_node = Crass.parse_properties(propstring).first
    sanitized_tree << sanitized_node << CRASS_SEMICOLON
  end

  Crass::Parser.stringify(sanitized_tree)
end

.scrub_css_attribute(node) ⇒ Object



105
106
107
108
# File 'lib/loofah/html5/scrub.rb', line 105

def scrub_css_attribute(node)
  style = node.attributes["style"]
  style.value = scrub_css(style.value) if style
end

.scrub_uri_attribute(attr_node) ⇒ Object



226
227
228
229
230
231
232
233
# File 'lib/loofah/html5/scrub.rb', line 226

def scrub_uri_attribute(attr_node)
  if allowed_uri?(attr_node.value)
    false
  else
    attr_node.remove
    true
  end
end