CS / ITS PREPCOURSE · EXERCISE 02 · SOFTWARE SECURITY

The festival guestbook

Make your message do more than the organisers expected. Then repair the page.

Local practice page · fictional content · messages disappear on reload

Leave a message

Ready for your first message.

Latest guestbook entry

Each submission replaces the previous entry.

No messages yet.

Your challenge

This starter currently displays plain text. Preserve useful formatting without returning to raw HTML insertion.

  1. Find EDIT HERE in this file.
  2. Use the bundled DOMPurify library to sanitise the message, then display the sanitised result as HTML.
  3. Allow exactly strong and em elements. Allow no attributes, including data and ARIA attributes.
  4. Run the cases in ../test-inputs.md. Allowed formatting must survive; event handlers, images, links, and other elements must not survive.

DOMPurify is bundled locally, including its license. You do not need a package manager or internet access.

Hints

Hint 1 · Sanitise before insertion

DOMPurify.sanitize(message, options) returns a sanitised HTML string. Assign that result to entry.innerHTML. Do not append the original message afterwards.

Hint 2 · Explicit allowlists

Use the options ALLOWED_TAGS and ALLOWED_ATTR. Disable the separate defaults for ALLOW_DATA_ATTR and ALLOW_ARIA_ATTR.

Hint 3 · Configuration
{ ALLOWED_TAGS: ['strong', 'em'], ALLOWED_ATTR: [],
  ALLOW_DATA_ATTR: false, ALLOW_ARIA_ATTR: false }

Keep evidence

Record your normal message, heading input, and JavaScript input in lab-record.md. Save your repaired page with a new filename. Demonstrate that your test messages behave correctly after repair.

MDN: Cross-site scripting · MDN: textContent