fix(docs): a posted doc cannot run script on the Booth's origin

Found by design-dev's impeccable run and confirmed at source. Python-Markdown
passes raw HTML through, and doc.html and booth.html render the result |safe.
A <script> in any session's .md ran on the Booth's origin, and a contract that
quoted <pre> opened a real one and swallowed the rest of the doc.

Operator ruling: escape raw HTML (not an allowlist).
- render_doc deregisters Python-Markdown's block and inline HTML processors,
  so raw HTML reaches the serializer as text and is escaped there. Fenced and
  inline code are unchanged.
- Every link href in a doc goes through links.is_safe_href after
  browser-style decoding. Python-Markdown keeps character references in
  attributes, so `java&#115;cript:` reached the browser as `javascript:`.
- is_safe_href reads a backslash as a slash, as a browser does in an http(s)
  URL: `/\evil.test` is `//evil.test`. This also closes the hole on the
  link board.
- A render that raises falls back to raw text, which the template escapes.

Two of 19 live .md files render differently. One is a contract losing the
quoted <pre> that swallowed it. The other is links.md, which renders as a
board, not through render_doc.

heid bug-hunt panel (4/4): the core claim held. Its two concrete edges (the
backslash twin, the unbounded render) are fixed here. Table
tests/mutations/doc_html.toml: 9/9 proved. Suite 951 -> 975.
This commit is contained in:
vh
2026-09-28 10:37:36 -07:00
parent 50bfc7b4ec
commit 190a75a0e1
8 changed files with 361 additions and 6 deletions
+9
View File
@@ -151,6 +151,15 @@ a crash mid-write cannot truncate a file into a shorter — and therefore quiete
template escapes it inside `<pre>`, and pre-escaping here double-encodes under
Jinja autoescape.
⚠ **The markdown case is the one `|safe` render in the repo, so it carries its
own escaping.** Raw HTML in a doc is escaped to text (the block and inline HTML
processors are deregistered), and every link href goes through
`links.is_safe_href` after browser-style decoding, where `java&#115;cript:` is
`javascript:` (and a backslash reads as a slash, so `/\evil.test` is
off-origin). A render that raises falls back to raw text, which the template
escapes. Until 2026-09-28 a posted `.md` could run script on the Booth's
origin. Anything else that renders author text `|safe` inherits these rules.
### 6. Every ordered collection has a stated, deterministic order
Operator directive, 2026-09-21. Not "usually stable" and not "whatever `rglob`