From 2e31733093077c00be495d5725c7930f6ac9083c Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:50:53 +0300 Subject: Security: Keep template errors out of production responses A failed render printed the error into the page: template names, the failing field, sometimes a piece of the data. In production that is now a plain "Something went wrong" with the detail in the log; in dev mode it stays on the page, escaped. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/server.go | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'internal/web') diff --git a/internal/web/server.go b/internal/web/server.go index f02dd68..f5d32d1 100644 --- a/internal/web/server.go +++ b/internal/web/server.go @@ -399,7 +399,13 @@ func (s *Server) renderStatus(w http.ResponseWriter, r *http.Request, status int w.WriteHeader(status) if err := s.tpl.render(w, v.Lang, name, v); err != nil { log.Printf("render %s: %v", name, err) - fmt.Fprintf(w, "
template error: %v
", err) + // The status is already out; say something went wrong without the + // detail (template paths and data internals belong in the log). + if s.cfg.Dev { + fmt.Fprintf(w, "
template error: %s
", htmlEscape(err.Error())) + return + } + fmt.Fprint(w, "

Something went wrong.

") } } -- cgit v1.2.3