Several error paths in HandleAppCreate and HandleAppUpdate call tmpl.ExecuteTemplate(writer, ...) directly instead of using h.renderTemplate(writer, tmpl, ...). The renderTemplate method renders into a buffer first and only writes to the ResponseWriter on success, preventing partial/corrupt HTML. The direct calls bypass this safety.
Affected Code
internal/handlers/app.go — HandleAppCreate:
nameErr:=validateAppName(name)ifnameErr!=nil{data["Error"]="Invalid app name: "+nameErr.Error()_=tmpl.ExecuteTemplate(writer,"app_new.html",data)// DIRECT — no bufferreturn}
internal/handlers/app.go — HandleAppUpdate:
nameErr:=validateAppName(newName)ifnameErr!=nil{// ..._=tmpl.ExecuteTemplate(writer,"app_edit.html",data)// DIRECT — no bufferreturn}repoURLErr:=validateRepoURL(request.FormValue("repo_url"))ifrepoURLErr!=nil{// ..._=tmpl.ExecuteTemplate(writer,"app_edit.html",data)// DIRECT — no bufferreturn}
Other error paths in the same functions correctly use h.renderTemplate.
Impact
If template execution fails partway through (e.g., missing template data), a partial HTML response is sent to the browser. This is unlikely in practice but violates the safety invariant that renderTemplate was specifically designed to enforce.
Fix
Replace all tmpl.ExecuteTemplate(writer, ...) calls with h.renderTemplate(writer, tmpl, ...).
## Bug
Several error paths in `HandleAppCreate` and `HandleAppUpdate` call `tmpl.ExecuteTemplate(writer, ...)` directly instead of using `h.renderTemplate(writer, tmpl, ...)`. The `renderTemplate` method renders into a buffer first and only writes to the ResponseWriter on success, preventing partial/corrupt HTML. The direct calls bypass this safety.
## Affected Code
**`internal/handlers/app.go` — `HandleAppCreate`:**
```go
nameErr := validateAppName(name)
if nameErr != nil {
data["Error"] = "Invalid app name: " + nameErr.Error()
_ = tmpl.ExecuteTemplate(writer, "app_new.html", data) // DIRECT — no buffer
return
}
```
**`internal/handlers/app.go` — `HandleAppUpdate`:**
```go
nameErr := validateAppName(newName)
if nameErr != nil {
// ...
_ = tmpl.ExecuteTemplate(writer, "app_edit.html", data) // DIRECT — no buffer
return
}
repoURLErr := validateRepoURL(request.FormValue("repo_url"))
if repoURLErr != nil {
// ...
_ = tmpl.ExecuteTemplate(writer, "app_edit.html", data) // DIRECT — no buffer
return
}
```
Other error paths in the same functions correctly use `h.renderTemplate`.
## Impact
If template execution fails partway through (e.g., missing template data), a partial HTML response is sent to the browser. This is unlikely in practice but violates the safety invariant that `renderTemplate` was specifically designed to enforce.
## Fix
Replace all `tmpl.ExecuteTemplate(writer, ...)` calls with `h.renderTemplate(writer, tmpl, ...)`.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bug
Several error paths in
HandleAppCreateandHandleAppUpdatecalltmpl.ExecuteTemplate(writer, ...)directly instead of usingh.renderTemplate(writer, tmpl, ...). TherenderTemplatemethod renders into a buffer first and only writes to the ResponseWriter on success, preventing partial/corrupt HTML. The direct calls bypass this safety.Affected Code
internal/handlers/app.go—HandleAppCreate:internal/handlers/app.go—HandleAppUpdate:Other error paths in the same functions correctly use
h.renderTemplate.Impact
If template execution fails partway through (e.g., missing template data), a partial HTML response is sent to the browser. This is unlikely in practice but violates the safety invariant that
renderTemplatewas specifically designed to enforce.Fix
Replace all
tmpl.ExecuteTemplate(writer, ...)calls withh.renderTemplate(writer, tmpl, ...).