From c0cc34d7ec3f31a862ba85ff3345619f3f40b40f Mon Sep 17 00:00:00 2001
From: Laszlo Bodor
Date: Fri, 18 Sep 2026 13:05:27 +0200
Subject: [PATCH] TEZ-4755: AMWebController: rendering improvements in
StaticAMView
Encode the configured history-url value when splicing it into the
StaticAMView redirect page so unexpected characters cannot alter the
surrounding HTML or JavaScript context. Adds a unit test.
Co-Authored-By: Claude Code
---
.../tez/dag/app/web/AMWebController.java | 60 ++++++++++++++++++-
.../tez/dag/app/web/TestAMWebController.java | 38 ++++++++++++
2 files changed, 95 insertions(+), 3 deletions(-)
diff --git a/tez-dag/src/main/java/org/apache/tez/dag/app/web/AMWebController.java b/tez-dag/src/main/java/org/apache/tez/dag/app/web/AMWebController.java
index e547dad520..b1a028fa07 100644
--- a/tez-dag/src/main/java/org/apache/tez/dag/app/web/AMWebController.java
+++ b/tez-dag/src/main/java/org/apache/tez/dag/app/web/AMWebController.java
@@ -921,17 +921,71 @@ private void render(PrintWriter pw) {
"To enable tracking url pointing to Tez UI, set the config " +
TezConfiguration.TEZ_HISTORY_URL_BASE + " in the tez-site.xml.
");
} else {
+ // historyUrl is derived from a submitter-supplied AM configuration
+ // property (tez.tez-ui.history-url.base). Escape it before splicing
+ // into the HTML attribute and the inline JS string literal so a
+ // value like ' or " cannot break out and run script in the browser
+ // of whoever opens the AM tracking URL.
pw.write("Redirecting to Tez UI
. If you are not redirected shortly, click " +
- "here
"
+ "here
"
);
pw.write("");
+ "window.location.replace('" + escapeJsString(historyUrl) + "');" +
+ "}, 0); ");
}
pw.write("