# Hugo with a CMS for Open-publishing: security with Markdown Attributes

**URL:** <https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150>\
**Category:** support\
**Created:** [October 14, 2021, 8:12pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150 "2021-10-14T20:12:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![iaeiou](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/iaeiou/32/15332_2.png) [@iaeiou](https://discourse.gohugo.io/u/iaeiou)\
**Post date:** [October 14, 2021, 8:12pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/1 "2021-10-14T20:12:43Z")

</div>

Hi there,

this is a follow-up on [a previous post](https://discourse.gohugo.io/t/hugo-cms-and-unsafe-true/35069) about using Hugo with a CMS for open-publishing.

To summarize, the original question was:

> Is it safe to use Hugo and a CMS for open-publishing with the setting `unsafe = true`?

The answer was crystal clear:

> No

Allright, so let’s use `unsafe = false`

But another important issue [was raised by @pamubay](https://discourse.gohugo.io/t/hugo-cms-and-unsafe-true/35069/4):

**Even if you set ‘unsafe = false’, the CMS user can trigger some Javascript** :

````auto
​```html {onclick="alert('xss')" onmouseenter="alert('xss-onmouseenter')"}
<h1>Hello World</h1>
​```

````

I checked the code on GitHub and found only these notes: [#8215 - markup/goldmark: Add attributes support for blocks](https://github.com/gohugoio/hugo/pull/8215) - no references to Javascript there.

I’m not in JS, so I’m not sure of the consequences. Can somebody enlighten me?  
Is it an expected behavior, or should I raise an issue on GitHub?

Overall, is Hugo a good choice for Open-publishing?

## References

- [Hugo + CMS and 'unsafe = true'](https://discourse.gohugo.io/t/hugo-cms-and-unsafe-true/35069)
- [Make unsafe: true the default setting for goldmark(?) · Issue #6581 · gohugoio/hugo · GitHub](https://github.com/gohugoio/hugo/issues/6581)
- [Configure markup](https://gohugo.io/getting-started/configuration-markup#goldmark)

---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [October 15, 2021, 3:42am UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/2 "2021-10-15T03:42:17Z")

</div>

Perhaps you should raise an issue at the main Hugo repo.

However if the project will not need to provide code examples in content files, you can always disable [standard syntax code blocks](https://gohugo.io/contribute/documentation/#standard-syntax) in the template with something like:

```auto
{{ replaceRE `\x60(.*?)\x60` `` .Content }}

```

Whenever backticks are found within a page’s `.Content` the above regular expression will capture everything between and remove it.

> [@iaeiou](#):
>
> Overall, is Hugo a good choice for Open-publishing?

Hugo is an open source static site generator. Static HTML is always safer than dynamic.

So for a project that will have users with no technical skills or users who are not trustworthy I think that Hugo would serve your use case, as long as the project’s backend (config + templates) is not accessible to plain users.

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [October 15, 2021, 5:39am UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/3 "2021-10-15T05:39:07Z")

</div>

The vulnerability exists in attributes for blocks, titles, and code fences (```).

To disable attributes for blocks and titles:

```auto
[markup.goldmark.parser.attribute]
block = false # default is false
title = false # default is true

```

You cannot disable attributes for code fences. Instead, disable code fence highlighting and use the [highlight shortcode](https://gohugo.io/content-management/syntax-highlighting/#highlight-shortcode).

```auto
[markup.highlight]
codeFences = false # default is true

```

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [October 16, 2021, 12:43am UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/4 "2021-10-16T00:43:08Z")

</div>

Two additional thoughts related to security…

First, make sure that [Inline Shortcodes](https://gohugo.io/templates/shortcode-templates/#inline-shortcodes) are disabled. This is the default setting.

```auto
enableInlineShortcodes = false # default is false

```

Second, make sure your shortcodes are safe. In particular, nothing like this:

```nohighlight
{{/* layouts/shortcodes/raw.html */}}
{{ .Inner }}

```

Because it would allow someone to do:

```auto
{{< raw >}}
<script>
  ...
</script>
{{< /raw >}}

```

---

<div class="post-metadata">

**Author:** ![iaeiou](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/iaeiou/32/15332_2.png) [@iaeiou](https://discourse.gohugo.io/u/iaeiou)\
**Post date:** [October 26, 2021, 7:53am UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/5 "2021-10-26T07:53:40Z")

</div>

Thank you for your precious pointers,

I double-checked the whole repo and this looks like an unexpected behavior: the [related branch](https://github.com/gohugoio/hugo/pull/8215) does not refer to such “feature” with Attributes. (See also the [release notes](https://gohugo.io/news/0.81.0-relnotes/) and the discussion [#7548](https://github.com/gohugoio/hugo/issues/7548))

I guess I should open an issue but my time (and my english!) is a bit narrow these days and this repo is sometime intimidating. Anyone feels like doing this?

> [@jmooring](#):
>
> You cannot disable attributes for code fences. Instead, disable code fence highlighting

Thanks a lot for your advanced knowledge. I would like to understand the reason behind this, but couldn’t find details. How to know precisely which attributes are affected?

> [@jmooring](#):
>
> disable code fence highlighting and use the [highlight shortcode](https://gohugo.io/content-management/syntax-highlighting/#highlight-shortcode).

I would prefer to stick to basic Markdown for two reasons:

- The content is portable with basic Markdown
- Shortcode syntax is too difficult for newcomers

That’s no big deal though, and if no simple solution exists I’ll add a component / button in NetlifyCMS and everything will be find 😃

Once again, thank you @alexandros and @jmooring for sharing, it’s good to know you’re around

---

<div class="post-metadata">

**Author:** ![iaeiou](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/iaeiou/32/15332_2.png) [@iaeiou](https://discourse.gohugo.io/u/iaeiou)\
**Post date:** [February 3, 2022, 5:52pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/6 "2022-02-03T17:52:06Z")

</div>

Hugo 0.91 introduces new features around this topic:

- [https://github.com/gohugoio/hugo/releases/tag/v0.91.0](https://github.com/gohugoio/hugo/releases/tag/v0.91.0)
- [Hugo's Security Model | Hugo](https://gohugo.io/about/security-model/)

(I had no time to check if it fixes everything though)

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [February 4, 2022, 12:12am UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/7 "2022-02-04T00:12:02Z")

</div>

v0.92.1 and earlier do _not_ address the concerns with JS attribute events.

Follow these:  
[https://github.com/gohugoio/hugo/issues/9463](https://github.com/gohugoio/hugo/issues/9463)  
[https://github.com/gohugoio/hugo/pull/9464](https://github.com/gohugoio/hugo/pull/9464)

---

<div class="post-metadata">

**Author:** ![iaeiou](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/iaeiou/32/15332_2.png) [@iaeiou](https://discourse.gohugo.io/u/iaeiou)\
**Post date:** [February 10, 2022, 11:20pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/8 "2022-02-10T23:20:26Z")

</div>

A fix was merged earlier today, thank you Joe for tackling this, and Bep for the quick review!

---

<div class="post-metadata">

**Author:** ![iaeiou](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/iaeiou/32/15332_2.png) [@iaeiou](https://discourse.gohugo.io/u/iaeiou)\
**Post date:** [February 10, 2022, 11:21pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/9 "2022-02-10T23:21:32Z")

</div>

/cc @pamubay

---

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/system/32/1_2.png) [@system](https://discourse.gohugo.io/u/system)\
**Post date:** [February 12, 2022, 11:22pm UTC](https://discourse.gohugo.io/t/hugo-with-a-cms-for-open-publishing-security-with-markdown-attributes/35150/10 "2022-02-12T23:22:23Z")

</div>

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.
