Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.
This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
install-safety-checker targets
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
51 lines
2.7 KiB
Go
51 lines
2.7 KiB
Go
package main
|
|
|
|
import "fmt"
|
|
|
|
func init() {
|
|
register(Check{
|
|
Seq: 220,
|
|
ID: "22",
|
|
Title: "No hand-rolled HTML sanitization (use bluemonday)",
|
|
Run: func(ctx *ScanContext, rep *Reporter) {
|
|
// Check 22: No hand-rolled HTML sanitization (use bluemonday)
|
|
fmt.Println("=== Check 22: No hand-rolled HTML sanitization (use bluemonday) ===")
|
|
var htmlSanViolations []htmlSanitizeViolation
|
|
for _, target := range ctx.backendTargets {
|
|
for _, v := range checkHTMLSanitize(target.root) {
|
|
v.file = prefixDisplayPath(target.display, v.file)
|
|
htmlSanViolations = append(htmlSanViolations, v)
|
|
}
|
|
}
|
|
for _, target := range ctx.pluginTargets {
|
|
for _, v := range checkHTMLSanitize(target.root) {
|
|
v.file = prefixDisplayPath(target.display, v.file)
|
|
htmlSanViolations = append(htmlSanViolations, v)
|
|
}
|
|
}
|
|
if len(htmlSanViolations) > 0 {
|
|
fmt.Printf(" FAIL: %d hand-rolled HTML sanitization pattern(s):\n", len(htmlSanViolations))
|
|
for _, v := range htmlSanViolations {
|
|
fmt.Printf(" %s:%d [%s] %s\n", v.file, v.line, v.rule, v.snippet)
|
|
}
|
|
fmt.Println(`
|
|
Fix: Use github.com/microcosm-cc/bluemonday for ALL HTML sanitization.
|
|
┌────────────────────────────────────────┬────────────────────────────────────────┐
|
|
│ Instead of │ Use │
|
|
├────────────────────────────────────────┼────────────────────────────────────────┤
|
|
│ regexp strip <tags> │ bluemonday.StrictPolicy().Sanitize(s) │
|
|
│ func stripHTML() { char loop } │ bluemonday.StrictPolicy().Sanitize(s) │
|
|
│ strings.NewReplacer("<br>","") │ bluemonday.StrictPolicy().Sanitize(s) │
|
|
│ helpers.StripHTML(s) │ bluemonday.StrictPolicy().Sanitize(s) │
|
|
└────────────────────────────────────────┴────────────────────────────────────────┘
|
|
Regex-based HTML stripping is a security risk — it misses edge cases,
|
|
nested tags, and encoded entities. bluemonday is battle-tested.`)
|
|
rep.Fail()
|
|
} else {
|
|
fmt.Println(" OK: No hand-rolled HTML sanitization detected")
|
|
printPerTargetOKLines(pluginTargetLabels(ctx.pluginTargets))
|
|
}
|
|
},
|
|
})
|
|
}
|