BUG: Template execution errors result in corrupt HTML responses #42

닫힘
clawbot가 2026-02-16 06:56:36 +01:00을 오픈 · 1개 댓글
공동작업자

Severity: MEDIUM

Files: Multiple handlers (setup.go, app.go, auth.go, dashboard.go)

Description

In all handlers, the pattern is:

err := tmpl.ExecuteTemplate(writer, "page.html", data)
if err != nil {
    h.log.Error("template execution failed", "error", err)
    http.Error(writer, "Internal Server Error", http.StatusInternalServerError)
}

The problem: ExecuteTemplate writes directly to the http.ResponseWriter. If the template partially renders before hitting an error, the HTTP 200 status and partial HTML have already been sent. The subsequent http.Error() call:

  1. Cannot change the already-sent 200 status code
  2. Appends "Internal Server Error" text to the partial HTML
  3. Results in a corrupt, half-rendered page

Suggested Fix

Render templates to a buffer first, then write to the response only on success:

var buf bytes.Buffer
err := tmpl.ExecuteTemplate(&buf, "page.html", data)
if err != nil {
    h.log.Error("template execution failed", "error", err)
    http.Error(writer, "Internal Server Error", http.StatusInternalServerError)
    return
}
buf.WriteTo(writer)

This is a common Go web pattern. Consider creating a helper method on Handlers.

## Severity: MEDIUM ## Files: Multiple handlers (setup.go, app.go, auth.go, dashboard.go) ## Description In all handlers, the pattern is: ```go err := tmpl.ExecuteTemplate(writer, "page.html", data) if err != nil { h.log.Error("template execution failed", "error", err) http.Error(writer, "Internal Server Error", http.StatusInternalServerError) } ``` The problem: `ExecuteTemplate` writes directly to the `http.ResponseWriter`. If the template partially renders before hitting an error, the HTTP 200 status and partial HTML have already been sent. The subsequent `http.Error()` call: 1. Cannot change the already-sent 200 status code 2. Appends "Internal Server Error" text to the partial HTML 3. Results in a corrupt, half-rendered page ## Suggested Fix Render templates to a buffer first, then write to the response only on success: ```go var buf bytes.Buffer err := tmpl.ExecuteTemplate(&buf, "page.html", data) if err != nil { h.log.Error("template execution failed", "error", err) http.Error(writer, "Internal Server Error", http.StatusInternalServerError) return } buf.WriteTo(writer) ``` This is a common Go web pattern. Consider creating a helper method on Handlers.
소유자

do it, using the helper method. apply it in all places this pattern appears. create a PR.

do it, using the helper method. apply it in all places this pattern appears. create a PR.
sneak 이 이슈 2026-02-16 07:05:45 +01:00 닫침
로그인하여 이 대화에 참여
참여자 2명
알림
마감일
마감일이 설정되지 않았습니다.
의존성

설정된 의존성 없음.

참조: sneak/upaas#42