Skip to content

render: do not leak JSON/XML encode errors - #65

Open
team-humaki wants to merge 1 commit into
go-chi:masterfrom
team-humaki:leak-json-encode-error
Open

team-humaki wants to merge 1 commit into
go-chi:masterfrom
team-humaki:leak-json-encode-error

Conversation

@team-humaki

Copy link
Copy Markdown

Fixes #57

JSON() currently writes enc.Encode's error string to the client. That can expose internal details.

On encode failure, respond with 500 and a generic status text. Same for XML() and event-stream marshal errors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Any concern render.JSON() can leak internal errors to outside?

1 participant