diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:50:53 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:50:53 +0300 |
| commit | 2e31733093077c00be495d5725c7930f6ac9083c (patch) | |
| tree | 6054e6d79452d40dc37c1df01844a4bb47b37a3f /internal | |
| parent | c3026c34b042cc044cddfc5674d5f5ad69bb845d (diff) | |
| download | blogspace-2e31733093077c00be495d5725c7930f6ac9083c.tar.gz blogspace-2e31733093077c00be495d5725c7930f6ac9083c.tar.bz2 blogspace-2e31733093077c00be495d5725c7930f6ac9083c.zip | |
Security: Keep template errors out of production responses
A failed render printed the error into the page: template names, the
failing field, sometimes a piece of the data. In production that is
now a plain "Something went wrong" with the detail in the log; in dev
mode it stays on the page, escaped.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal')
| -rw-r--r-- | internal/web/server.go | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/internal/web/server.go b/internal/web/server.go index f02dd68..f5d32d1 100644 --- a/internal/web/server.go +++ b/internal/web/server.go @@ -399,7 +399,13 @@ func (s *Server) renderStatus(w http.ResponseWriter, r *http.Request, status int w.WriteHeader(status) if err := s.tpl.render(w, v.Lang, name, v); err != nil { log.Printf("render %s: %v", name, err) - fmt.Fprintf(w, "<pre>template error: %v</pre>", err) + // The status is already out; say something went wrong without the + // detail (template paths and data internals belong in the log). + if s.cfg.Dev { + fmt.Fprintf(w, "<pre>template error: %s</pre>", htmlEscape(err.Error())) + return + } + fmt.Fprint(w, "<p>Something went wrong.</p>") } } |
