Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-22710

Implement security sanitization of RSS feeds and other included content

    XMLWordPrintable

Details

    • 1
    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      A great improvement for RSS macros would be to implement "cleansing" or "sanitization" of external RSS feeds. This may be something that is configured at the admin level or in the macro level – I'd prefer it to be a global admin requirement. Having externally linked content is a security risk, and for that Atlassian should be commended for the Whitelist function. But the risk remains that malicious content could be brought in through a whitelisted feed.

      There are plenty of projects that are dedicated to aggregation, modification, and security sanitization of RSS content. http://simplepie.org/ is an example of the various projects that do this. The existing tools sanitize the RSS feeds by stripping out entire tags which are insecure as well as individual attributes of otherwise secure tags which may be insecure. Depending on how the projects are licensed and Atlassian's policies for inclusion of third-party code, this may be a fairly simple feature to implement.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              c15e2bcd81f1 Justin Clarke
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: