security: harden template output escaping#761
Merged
RussH merged 8 commits intoopencats:masterfrom May 1, 2026
Merged
Conversation
25e0c32 to
9bcab32
Compare
RussH
approved these changes
May 1, 2026
Member
RussH
left a comment
There was a problem hiding this comment.
This looks clean - so long as there's no html expected in activities or questionnaire responses. The tests are good, too - thank you!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR centralizes template output escaping helpers and applies them to selected OpenCATS UI outputs.
It adds reusable escaping methods for HTML text, HTML attributes, URLs, and JavaScript string literals, then updates existing template output to use the appropriate helper for each context. The goal is to make escaping behavior more consistent and reduce the risk of XSS issues while keeping the changes minimal and close to the existing template structure.
The updated areas include template header output, candidate detail page output, contact detail page output, company detail page output, job order detail page output and activity-related output.
The changes intentionally avoid business logic changes, SQL changes, permission changes and layout restructuring. Activity notes continue to preserve line breaks where applicable, but are escaped at output time before formatting.