a2ui-project / a2ui-project/a2ui
[BUG]: Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization
- 主要语言
- TypeScript
- 星标
- 16.4k
- 派生
- 1.3k
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 134
描述
# Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization
Repository: https://github.com/a2ui-project/a2ui (sample project `samples/community/client/angular/projects/a2a-chat-canvas`, v0.0.1)
CWE: CWE-79 (Improper Neutralization of Input During Web Page Generation — XSS)
## Summary
The default implementation of the chat canvas's text-part renderer returns `sanitizer.bypassSecurityTrustHtml()`, and the component binds the result via `@HostBinding('innerHTML')`. Remote agent text parts are therefore rendered as raw HTML inside the host application's origin. The class does not actually render markdown; it passes the original HTML through.
## Affected code
- `samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts:29`
- Rendered at `default-text-part.ts:60-71` (`@HostBinding('innerHTML')`)
- Wired as the default by `markdown-renderer-service.ts:31-36` and `config.ts:103`
## Observed behavior
An agent message containing `` executes in the host page (standard stored-XSS consequence of the SafeHtml bypass).
## Context
This is community sample code (v0.0.1), not an official npm release; it is filed because the unsafe renderer is the default configuration of the sample, so applications copying the sample inherit the behavior as-is.
## Suggested remediation
Make a sanitizing pipeline the default renderer — e.g. the `@a2ui/markdown-it` path used elsewhere (markdown-it with `html: false` + DOMPurify).
贡献指南
调研方向
Examine the files mentioned: sanitizer-markdown-renderer-service.ts, default-text-part.ts, markdown-renderer-service.ts, and config.ts. Understand how the default text renderer bypasses Angular's sanitization. The fix involves replacing the bypass with a safe pipeline, possibly using @a2ui/markdown-it with html: false and DOMPurify. Test by creating a message with an XSS payload and verifying it no longer executes.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- angular, typescript
- 领域
- frontend, security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 活跃
- 描述清晰度
- 描述清楚
- 新手友好度
- 65/100