![Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack](https://cdn.sanity.io/images/cgdhsj6q/production/6af25114feaaac7179b18127c83327568ff592d1-1024x1024.webp?w=800&fit=max&auto=format)
Security News
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack
Polyfill.io has been serving malware for months via its CDN, after the project's open source maintainer sold the service to a company based in China.
express-secure-handlebars
Advanced tools
Readme
We enhance the express-handlebars server-side view engine by leveraging the secure-handlebars for defending against Cross-Site Scripting (XSS). Hence, web applications can be automatically secured by contextual output escaping.
express-handlebars
with express-secure-handlebars
(i.e., to update those require()
calls as well as the dependency in your package.json
). The nitty-gritties of filter choices and integrations are all automated!For more details, kindly refer to the introductions to secure-handlebars and xss-filters.
npm install express-secure-handlebars --save
Simply replace express-handlebars
with the express-secure-handlebars
package in all require()
!
Based on the basic example of ExpressHandlebars, here we show an example app that can be secured only with our package.
views/profile.handlebars:
Given that there is a very typical handlebars template file written like so to incorporate user inputs. The enhanced package can secure the web application by automatically applying context-sensitive output filters, which otherwise is still subject to XSS attacks if using the default escaping approach (e.g., when url is javascript:alert(1) or onclick=alert(1)).
<h1>Example App: {{title}}</h1>
...
<div>User-provided URL: <a href="{{url}}">{{url}}</a></div>
...
views/layouts/main.handlebars:
Same as the Handlebars original example, this file serves as the HTML page wrapper which can be reused for the different views of the app. {{{body}}} is used as a placeholder for where the main content should be rendered.
<!DOCTYPE html>
<html>
<head><meta charset="utf-8"><title>{{title}}</title></head>
<body>
{{{body}}}
</body>
</html>
app.js:
A super simple Express app that registers the Handlebars view engine.
var express = require('express'),
// The only difference is to replace 'express-handlebars' with our enhanced package.
// exphbs = require('express-handlebars');
exphbs = require('express-secure-handlebars');
var app = express(),
hbs = exphbs.create({ /* config */ });
app.engine('handlebars', hbs.engine);
app.set('view engine', 'handlebars');
app.use('/profile', function (req, res) {
res.render('profile', {
title: 'User Profile',
url: req.query.url // an untrusted user input
});
});
app.listen(3000);
Please refer to the section documented in secure-handlebars.
Please refer to the section documented in secure-handlebars.
Apply your changes to files in src/, and then run the tests.
npm test
This software is free to use under the Yahoo Inc. BSD license. See the LICENSE file for license text and copyright information.
FAQs
Secure Express/Handlebars with Context Parser
We found that express-secure-handlebars demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Polyfill.io has been serving malware for months via its CDN, after the project's open source maintainer sold the service to a company based in China.
Security News
OpenSSF is warning open source maintainers to stay vigilant against reputation farming on GitHub, where users artificially inflate their status by manipulating interactions on closed issues and PRs.
Security News
A JavaScript library maintainer is under fire after merging a controversial PR to support legacy versions of Node.js.