The Runtime Theory
mediumowasp-cheat-sheet#contextual-encoding#secure-defaults

Secure an Untrusted Text Rendering Path

Trace untrusted input into a web page, identify the output context, and choose encoding or sanitization at the correct boundary.

The Runtime Theory Team1 min read
Solve it

Solving happens on the judge — come back and mark it done

Sample cases

inRender user text into an HTML text node

outUse framework-safe text rendering or context-appropriate output encoding

inRender user text into a URL or HTML attribute

outValidate the allowed value and apply encoding suitable for that exact context

inAllow limited user-authored rich HTML

outUse a maintained sanitizer with an explicit allowlist; encoding alone changes the intended markup

Review a small page that renders a user profile name, link, and optional rich-text description. For each value, identify who controls it, where it is stored, and the browser context where it is inserted.

Replace unsafe string concatenation with framework-safe rendering. Validate URL schemes and destinations; use a maintained sanitizer only when rich HTML is a real product requirement. Add tests for quotes, angle brackets, event-handler attributes, and javascript: URLs without assuming one escape function is safe in every context.

The linked OWASP guide provides context-specific defenses. A web application firewall is not a substitute for safe output handling in the application.

One dispatch a week

The trace behind each problem, the tradeoff that explains it, and one technical dispatch per week — no noise.

One technical dispatch per week. No noise.

Not started

Sign in to save your learning progress.

Sign in to save