From 733a9cf8702ef8e6dc404a15d8217ff08ea9c59f Mon Sep 17 00:00:00 2001 From: mvdbeek Date: Thu, 6 Feb 2025 17:33:27 +0100 Subject: [PATCH 1/5] Set content-type to text/plain if dataset not safe We only care about XSS in the content of the webapp, and for that it is sufficient to set the content-type to text/plain. --- lib/galaxy/datatypes/data.py | 20 +++++++------------- 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/lib/galaxy/datatypes/data.py b/lib/galaxy/datatypes/data.py index 66462f51740..61a17f551ed 100644 --- a/lib/galaxy/datatypes/data.py +++ b/lib/galaxy/datatypes/data.py @@ -60,7 +60,6 @@ from galaxy.util.markdown import ( indicate_data_truncated, literal_via_fence, ) -from galaxy.util.sanitize_html import sanitize_html from galaxy.util.zipstream import ZipstreamWrapper from . import ( dataproviders as p_dataproviders, @@ -635,21 +634,16 @@ class Data(metaclass=DataMeta): return result def _yield_user_file_content(self, trans, from_dataset: HasCreatingJob, filename: str, headers: Headers) -> IO: - """This method is responsible for sanitizing the HTML if needed.""" + """This method sets the content type header to text/plain if we don't trust html content.""" if trans.app.config.sanitize_all_html and headers.get("content-type", None) == "text/html": - # Sanitize anytime we respond with plain text/html content. # Check to see if this dataset's parent job is allowlisted # We cannot currently trust imported datasets for rendering. - if not from_dataset.creating_job.imported and from_dataset.creating_job.tool_id.startswith( - tuple(trans.app.config.sanitize_allowlist) - ): - return open(filename, mode="rb") - - # This is returning to the browser, it needs to be encoded. - # TODO Ideally this happens a layer higher, but this is a bad - # issue affecting many tools - with open(filename) as f: - return sanitize_html(f.read()).encode("utf-8") + content_type = "text/html" + if from_dataset.creating_job.imported: + content_type = "text/plain" + if not from_dataset.creating_job.tool_id.startswith(tuple(trans.app.config.sanitize_allowlist)): + content_type = "text/plain" + headers["content-type"] = content_type return open(filename, mode="rb") From 9233d19caa61b95f4f27516841f4ae7cbc614d68 Mon Sep 17 00:00:00 2001 From: mvdbeek Date: Fri, 7 Feb 2025 12:42:40 +0100 Subject: [PATCH 2/5] Display warning if ouput sanitized --- .../entry/analysis/modules/CenterFrame.vue | 131 ++++++++++++------ client/src/entry/analysis/router.js | 1 + lib/galaxy/datatypes/data.py | 2 + 3 files changed, 94 insertions(+), 40 deletions(-) diff --git a/client/src/entry/analysis/modules/CenterFrame.vue b/client/src/entry/analysis/modules/CenterFrame.vue index 20e6a0cb080..01edade50b8 100644 --- a/client/src/entry/analysis/modules/CenterFrame.vue +++ b/client/src/entry/analysis/modules/CenterFrame.vue @@ -1,46 +1,97 @@ -