fix: buffer template execution to prevent corrupt HTML responses (closes #42)
Add renderTemplate helper method on Handlers that renders templates to a bytes.Buffer first, then writes to the ResponseWriter only on success. This prevents partial/corrupt HTML when template execution fails partway through. Applied to all template rendering call sites in: - setup.go (HandleSetupGET, renderSetupError) - auth.go (HandleLoginGET, HandleLoginPOST error paths) - dashboard.go (HandleDashboard) - app.go (HandleAppNew, HandleAppCreate, HandleAppDetail, HandleAppEdit, HandleAppUpdate, HandleAppDeployments)
This commit is contained in:
@@ -2,6 +2,7 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
@@ -18,6 +19,7 @@ import (
|
||||
"git.eeqj.de/sneak/upaas/internal/service/auth"
|
||||
"git.eeqj.de/sneak/upaas/internal/service/deploy"
|
||||
"git.eeqj.de/sneak/upaas/internal/service/webhook"
|
||||
"git.eeqj.de/sneak/upaas/templates"
|
||||
)
|
||||
|
||||
// Params contains dependencies for Handlers.
|
||||
@@ -80,6 +82,28 @@ func (h *Handlers) addGlobals(
|
||||
return data
|
||||
}
|
||||
|
||||
// renderTemplate executes the named template into a buffer first, then writes
|
||||
// to the ResponseWriter only on success. This prevents partial/corrupt HTML
|
||||
// responses when template execution fails partway through.
|
||||
func (h *Handlers) renderTemplate(
|
||||
writer http.ResponseWriter,
|
||||
tmpl *templates.TemplateExecutor,
|
||||
name string,
|
||||
data any,
|
||||
) {
|
||||
var buf bytes.Buffer
|
||||
|
||||
err := tmpl.ExecuteTemplate(&buf, name, data)
|
||||
if err != nil {
|
||||
h.log.Error("template execution failed", "error", err)
|
||||
http.Error(writer, "Internal Server Error", http.StatusInternalServerError)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
_, _ = buf.WriteTo(writer)
|
||||
}
|
||||
|
||||
func (h *Handlers) respondJSON(
|
||||
writer http.ResponseWriter,
|
||||
_ *http.Request,
|
||||
|
||||
Reference in New Issue
Block a user