This is an automated email from the ASF dual-hosted git repository.
cziegeler pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/sling-org-apache-sling-xss.git
The following commit(s) were added to refs/heads/master by this push:
new 3eb1753 docs: document XSS escaping requirement for web console
plugin (#68)
3eb1753 is described below
commit 3eb17534b5d8f873c92ff44e4031250711f6b325
Author: Carsten Ziegeler <[email protected]>
AuthorDate: Thu Jul 16 14:17:05 2026 +0200
docs: document XSS escaping requirement for web console plugin (#68)
Co-authored-by: Maia <maia@noreply>
---
AGENTS.md | 2 +-
README.md | 1 +
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/AGENTS.md b/AGENTS.md
index 618d399..ff58921 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -74,6 +74,7 @@ pom.xml
- Public API (`org.apache.sling.xss`) is versioned via `@Version` in
`package-info.java`; increment according to OSGi semantic versioning when
changing interfaces.
- ESAPI, Batik, and owasp-html-sanitizer are embedded via `bnd.bnd` private
packages — do not add OSGi `Import-Package` for them.
- Invalid href metrics are emitted via `XSSMetricsService` and
`org.apache.sling.commons.metrics` when a `MetricsService` is available
(optional dynamic DS reference).
+- In the web console plugin, always HTML-escape request-derived values (for
example `consoleRoot`) before interpolating into markup
(`StringEscapeUtils.escapeHtml4`).
- Formatting is enforced by Spotless (inherited from `sling-bundle-parent`).
Run `mvn spotless:apply` before committing.
- 4-space indentation, no wildcard imports in non-generated code.
- License header required on every source file (enforced by Apache RAT).
@@ -108,4 +109,3 @@ pom.xml
<!-- sling-security-default:start -->
The threat model for this project is
https://github.com/apache/sling/blob/master/docs/threat-model.md .
<!-- sling-security-default:end -->
-
diff --git a/README.md b/README.md
index 1c044d4..d14d3fd 100644
--- a/README.md
+++ b/README.md
@@ -21,6 +21,7 @@ See the JavaDoc of each service for the complete API surface.
- Uses `owasp-java-html-sanitizer` for HTML sanitization.
- Embeds ESAPI, Batik CSS, and HTML sanitizer packages as private bundle
packages to avoid OSGi import conflicts.
- Includes optional invalid-href metrics integration via Sling Commons Metrics.
+- Web console rendering escapes request-derived values (for example
`consoleRoot`) before interpolation to prevent XSS in the plugin UI.
- Excludes legacy/conflicting transitive logging dependencies such as
`commons-logging` and does not depend on Log4j 1.x.
## Build and test