nishat-06 opened a new pull request, #8617: URL: https://github.com/apache/hadoop/pull/8617
### Description of PR The apps tables in the RM, ApplicationHistory, FairScheduler and Router web UIs build their rows into a `StringBuilder` and emit the result inside a `<script>` element as `var appsTableData=...`. Every application-supplied column in that array (user, name, type, tags, queue) already goes through `escapeEcmaScript(escapeHtml4(...))`, but the tracking URL is concatenated straight into `href='...'`, and `ApplicationReport.getTrackingUrl()` hands back `RMAppAttemptImpl.originalTrackingUrl` verbatim for an unmanaged AM, so the string a client passes to `registerApplicationMaster` reaches the page unfiltered. A tracking URL holding a quote or a `</script>` closes the attribute or the script element and runs in the browser of anyone listing applications, so the escaping the neighbouring columns already use is applied here too. The Router copy has an `escape()` helper of its own that this one call site was skipping. ### How was this patch tested? New `TestAppsBlock#testTrackingUrlIsEscaped` renders `AppsBlock` with a report whose tracking URL carries a `</script><script>` payload; it fails on trunk and passes with the change. `TestAppsBlock`, `TestRMWebApp`, `TestRMWebAppFairScheduler`, `TestAppPage` and `TestFederationWebApp` all pass, and checkstyle reports nothing new on the touched files. ### For code changes: - [ ] Does the title or this PR starts with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')? - [ ] Object storage: have the integration tests been executed and the endpoint declared according to the connector-specific documentation? - [ ] If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under [ASF 2.0](http://www.apache.org/legal/resolved.html#category-a)? - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, `NOTICE-binary` files? ### AI Tooling If an AI tool was used: - [ ] The PR includes the phrase "Contains content generated by <tool>" where <tool> is the name of the AI tool used. - [ ] My use of AI contributions follows the ASF legal policy https://www.apache.org/legal/generative-tooling.html -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
