package main import "fmt" func init() { register(Check{ Seq: 220, ID: "22", Title: "No hand-rolled HTML sanitization (use bluemonday)", Run: func(ctx *ScanContext, rep *Reporter) { // Check 22: No hand-rolled HTML sanitization (use bluemonday) fmt.Println("=== Check 22: No hand-rolled HTML sanitization (use bluemonday) ===") var htmlSanViolations []htmlSanitizeViolation for _, target := range ctx.backendTargets { for _, v := range checkHTMLSanitize(target.root) { v.file = prefixDisplayPath(target.display, v.file) htmlSanViolations = append(htmlSanViolations, v) } } for _, target := range ctx.pluginTargets { for _, v := range checkHTMLSanitize(target.root) { v.file = prefixDisplayPath(target.display, v.file) htmlSanViolations = append(htmlSanViolations, v) } } if len(htmlSanViolations) > 0 { fmt.Printf(" FAIL: %d hand-rolled HTML sanitization pattern(s):\n", len(htmlSanViolations)) for _, v := range htmlSanViolations { fmt.Printf(" %s:%d [%s] %s\n", v.file, v.line, v.rule, v.snippet) } fmt.Println(` Fix: Use github.com/microcosm-cc/bluemonday for ALL HTML sanitization. ┌────────────────────────────────────────┬────────────────────────────────────────┐ │ Instead of │ Use │ ├────────────────────────────────────────┼────────────────────────────────────────┤ │ regexp strip │ bluemonday.StrictPolicy().Sanitize(s) │ │ func stripHTML() { char loop } │ bluemonday.StrictPolicy().Sanitize(s) │ │ strings.NewReplacer("
","") │ bluemonday.StrictPolicy().Sanitize(s) │ │ helpers.StripHTML(s) │ bluemonday.StrictPolicy().Sanitize(s) │ └────────────────────────────────────────┴────────────────────────────────────────┘ Regex-based HTML stripping is a security risk — it misses edge cases, nested tags, and encoded entities. bluemonday is battle-tested.`) rep.Fail() } else { fmt.Println(" OK: No hand-rolled HTML sanitization detected") printPerTargetOKLines(pluginTargetLabels(ctx.pluginTargets)) } }, }) }