aboutsummaryrefslogtreecommitdiffstats
path: root/internal
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:50:53 +0300
committergrm <grm@eyesin.space>2026-09-18 13:50:53 +0300
commit2e31733093077c00be495d5725c7930f6ac9083c (patch)
tree6054e6d79452d40dc37c1df01844a4bb47b37a3f /internal
parentc3026c34b042cc044cddfc5674d5f5ad69bb845d (diff)
downloadblogspace-2e31733093077c00be495d5725c7930f6ac9083c.tar.gz
blogspace-2e31733093077c00be495d5725c7930f6ac9083c.tar.bz2
blogspace-2e31733093077c00be495d5725c7930f6ac9083c.zip
Security: Keep template errors out of production responses
A failed render printed the error into the page: template names, the failing field, sometimes a piece of the data. In production that is now a plain "Something went wrong" with the detail in the log; in dev mode it stays on the page, escaped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal')
-rw-r--r--internal/web/server.go8
1 files changed, 7 insertions, 1 deletions
diff --git a/internal/web/server.go b/internal/web/server.go
index f02dd68..f5d32d1 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -399,7 +399,13 @@ func (s *Server) renderStatus(w http.ResponseWriter, r *http.Request, status int
w.WriteHeader(status)
if err := s.tpl.render(w, v.Lang, name, v); err != nil {
log.Printf("render %s: %v", name, err)
- fmt.Fprintf(w, "<pre>template error: %v</pre>", err)
+ // The status is already out; say something went wrong without the
+ // detail (template paths and data internals belong in the log).
+ if s.cfg.Dev {
+ fmt.Fprintf(w, "<pre>template error: %s</pre>", htmlEscape(err.Error()))
+ return
+ }
+ fmt.Fprint(w, "<p>Something went wrong.</p>")
}
}