static page to display query parameter values with least security concern?

Viewed 50

our server needs to redirect to a static page at the end of a process with an URL like mypage?key1=val1&key2=val2

The task of mypage is to extract values of key1 and key2 and display them. The query parameters are limited to key1 and key2. For smooth user experience, we'd like to display val1 and val2 in the page. Mostly working as a backend team, we are not frontend web security veterans to have a full comprehensive list of security sanitizing we need to do for val1 and val2. Rather than playing with all the security fancy tricks to filter the values, I am wondering if we can just display the values as plain text. So mypage itself is just a plain text, without any html tags for browser to interpret. A few factors playing on our side,

  1. the request to mypage should ALWAYS come from our server (domain fixed)
  2. key1 and key2 are fixed
  3. no need for fancy layout or css to display the values

Can web development gurus share some hints on what language, framework that gives us the most optimal choice to stand up mypage with least efforts and most secure in the meanwhile? Many thanks in advance

1 Answers

I think the biggest threat you are facing is a Cross-Site Scripting (XSS) vulnerability.

Right solution highly depends on the technology stack you are using. May be that if you are running Angular or React application in the right way, you won't need to do anything, as proper context sensitive escaping will be done for you. The problem arises when you have non of the above and you need to write JS + HTML on your own. In this case you would need to escape the val1 and val2 values for the context they are to be used in (I assume - simple HTML escape will do). If you don't wish to write such code yourself, feel free to use something like https://www.npmjs.com/package/escape-html.

Related