My Own Python Web Framework
healeycodes.com
healeycodes.com
def render(data):
return f"<h1>Last regenerated at: {data['time']}</h1>", {}
What if data['time'] is '<script>alert("oops!")</script>'?While JavaScript's template literals [1] would allow this kind of API to work (because the prefix of the template string can be a function that escapes the parameters), Python's f-strings doesn't have equivalent functionality. The tuple returned from the render function should probably include an additional item containing the parameters for the format string (which shouldn't be an f-string).
See also [2].
[1] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
[2] https://en.wikipedia.org/wiki/Uncontrolled_format_string
Also, it's not just about JavaScript. If values aren't properly encoded as HTML, the app is just plain broken when it tries to display text that contains certain character sequences. For example, the app is not capable of displaying the data value "To create a heading in HTML, use <h1>My heading</h1>".
The values need to be separated from the format string and passed through an encoding function such as html.escape [2]. Django learned this lesson 15 years ago in version 1.0 [3].
[1] https://github.com/healeycodes/jar#fresh-pages
[2] https://docs.python.org/3/library/html.html#html.escape
[3] https://docs.djangoproject.com/en/3.2/releases/1.0-porting-g...
Is it a reasonable expectation that every dev and blog posts must rehash all of OWASP and audit their experimental frameworks (now several years in the making) before publishing?
Edit: Sitting down and writing my own WSGI web library is on my bucket list, I just have other items I want to do more.
I did something like that many years ago: https://github.com/susam/ice
Documentation: https://icepy.readthedocs.io/en/latest/tutorial.html
I don’t use it anymore though. By the time I finished writing it, I was already hooked to Common Lisp and Hunchentoot for web development. So this tiny WSGI microframework remained as a hobby project.
Just was curious if anyone solved this DX issue in a more elegant way.