CS / ITS PREPCOURSE · EXERCISE 02 · SOFTWARE SECURITY
The festival guestbook
Make your message do more than the organisers expected. Then repair the page.
Local practice page · fictional content · messages disappear on reload
Leave a message
Ready for your first message.
Latest guestbook entry
Each submission replaces the previous entry.
Your challenge
This starter currently displays plain text. Preserve useful formatting without returning to raw HTML insertion.
- Find
EDIT HEREin this file. - Use the bundled DOMPurify library to sanitise the message, then display the sanitised result as HTML.
- Allow exactly
strongandemelements. Allow no attributes, including data and ARIA attributes. - Run the cases in
../test-inputs.md. Allowed formatting must survive; event handlers, images, links, and other elements must not survive.
DOMPurify is bundled locally, including its license. You do not need a package manager or internet access.
Hints
Hint 1 · Sanitise before insertion
DOMPurify.sanitize(message, options) returns a sanitised HTML string. Assign that result to entry.innerHTML. Do not append the original message afterwards.
Hint 2 · Explicit allowlists
Use the options ALLOWED_TAGS and ALLOWED_ATTR. Disable the separate defaults for ALLOW_DATA_ATTR and ALLOW_ARIA_ATTR.
Hint 3 · Configuration
{ ALLOWED_TAGS: ['strong', 'em'], ALLOWED_ATTR: [],
ALLOW_DATA_ATTR: false, ALLOW_ARIA_ATTR: false }Keep evidence
Record your normal message, heading input, and JavaScript input in lab-record.md. Save your repaired page with a new filename. Demonstrate that your test messages behave correctly after repair.