chore(security): whitelist font-family against FontRegistry on HTML emit #205

Closed
opened 2026-07-03 12:00:59 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-03 12:00:59 +00:00 (Migrated from github.com)

Origin

Post-batch security review (2026-07-03), defense-in-depth. Not currently exploitable — the font picker only offers the 7 hardcoded FontRegistry CSS stacks, the whole declaration is wrapped in escapeAttr (a value can't break out of the style="…" attribute or inject a tag), and reply/forward reduces untrusted sender HTML to plaintext before it can reach RichStyle.FontFamily. This is insurance against those invariants changing.

Problem

RichTextHtml.inlineCss (~line 200) and baseCss (~line 29) interpolate the font-family value into the emitted HTML style attribute raw (no escaping of ;/:). If a non-registry value ever reached emit, the worst case is a sibling CSS-property injection inside the attribute.

Scope

  • On HTML emit, constrain the font-family value to the known-good FontRegistry stacks (whitelist) — or otherwise restrict it to a safe charset — dropping/defaulting anything unrecognized instead of emitting it raw.
  • Unit test: a RichStyle.FontFamily carrying an unexpected value (e.g. Arial; color:red) does not appear raw in the emitted HTML.

Files

richtext/RichTextHtml.kt; ui/compose/format/ FontRegistry (source of the whitelist).

Notes

Defense-in-depth only — no behavior change for the built-in fonts. Origin: post-batch security review of PRs #194–#201.

## Origin Post-batch security review (2026-07-03), defense-in-depth. **Not currently exploitable** — the font picker only offers the 7 hardcoded `FontRegistry` CSS stacks, the whole declaration is wrapped in `escapeAttr` (a value can't break out of the `style="…"` attribute or inject a tag), and reply/forward reduces untrusted sender HTML to plaintext before it can reach `RichStyle.FontFamily`. This is insurance against those invariants changing. ## Problem `RichTextHtml.inlineCss` (~line 200) and `baseCss` (~line 29) interpolate the `font-family` value into the emitted HTML `style` attribute raw (no escaping of `;`/`:`). If a non-registry value ever reached emit, the worst case is a sibling CSS-property injection inside the attribute. ## Scope - On HTML emit, constrain the `font-family` value to the known-good `FontRegistry` stacks (whitelist) — or otherwise restrict it to a safe charset — dropping/defaulting anything unrecognized instead of emitting it raw. - Unit test: a `RichStyle.FontFamily` carrying an unexpected value (e.g. `Arial; color:red`) does not appear raw in the emitted HTML. ## Files `richtext/RichTextHtml.kt`; `ui/compose/format/` `FontRegistry` (source of the whitelist). ## Notes Defense-in-depth only — no behavior change for the built-in fonts. Origin: post-batch security review of PRs #194–#201.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#205