1f8ddb8a52 content: clarify resources front matter key descriptions e064ab8528 content: Add deprecation badges to module config page 727ca5563a github: Add push trigger to lint workflow 64dd5c9886 content: Fix typo c5bc6b6515 github: Fix lint workflow faec0c3a0a github: Combine linting actions into a single workflow 06112aeaf2 theme: Miscellaneous template edits 75d4902270 theme: Format templates with gotmplfmt fec2e2a67e content: Document that the language code in a file name must be lowercase 9dbd841ba6 content: Document the src attribute in the Page Resources metadata reference fd3ffef985 content: Fix "build from source" instructions for Windows af4c9cd4d7 content: Miscellaneous edits 408d8b2f0a content: Miscellaneous edits e8804afe6e content: Fix typo d98276be30 content: Updates for v0.161.0 01b1f8fa12 content: Note merge limitation for slice configuration values d2b18f0c8d content: Document page matcher usage for cascading values 45e5bd9ab3 content: Update Cloudflare Worker host/deploy guide b83726b89a content: Document fallback rendering for fenced code blocks 8f1eeb42bc content: Update reference for source code shortcode e8da56303b content: Add gotmplfmt to list of VS Code extensions 950fabbfd6 content: Update FAQ on feature availability error 6411146d24 content: Update quick start guide 38cc39fd51 content: Add Hugo Shortcodes to list of VS Code extensions 72d98b107b content: Misc updates to get validators to pass 9fb0e1ca35 Add a paragraph about sec boundaries e6abf5644f content: Improve syntax highlighting documentation c06193bd1a content: Update go-i18n package reference ce58fef945 Hugo 0.161.1 c7e0f63385 content: Fix package references 7f15fb3bf9 data: Regen docshelper 7483d53b55 Update HUGO_VERSION to 0.161.0 c4abcdb45f security: Add a bullet point about "pragmatic defaults" 3cd7492862 content: Improve explanation of mount removal in module configurations 4099f07bb9 content: Update GitHub Pages workflow example a6c9853a58 content: Fix typo e6f79a938b Update netlify.toml abda3d6659 content: Update Action versions in GitHub Pages workflow example 55dd288fa9 content: Add GitCMS to front-ends tools list 21081f6d49 content: Remove outdated new-in badges b2ec263884 content: Update version references 825e0b8ea9 One more CSS var adjustment 85f95a899b Adjust css.Build var docs a little df48288002 content: Updates for v0.160.0 a82a9b9797 Update HUGO_VERSION to 0.160.0 1155747dc4 content: Improve CSS processing feature description f6ce893974 content: Add css.Build to features 67b8ed1198 content: Fix typos 0f62a67863 content: Fix typo dbb42aed4a content: Document the deploy edition 549f30f933 content: De-emphasize references to the extended edition 8f5c9782d4 content: Add Pages CMS to front-ends documentation b2bfc3af48 Update HUGO_VERSION to 0.159.2 3793156fc5 content: Fix typos bacd4824ef content: Specify function namespace in example 7f2dc0d40a Regen docs.yml 65a851f731 Update HUGO_VERSION to 0.159.1 ce05fe3fc0 content: Adjust variable references in build script examples 8a04f9fe64 content: Improve hosting build script examples 67962ce05c content: Link to Codeberg Pages 404 handling fd248f57ed content: Identify esbuild as the foundation for build functions 62f02879fd content: Remove outdated content 553c407f9e content: Miscellaneous corrections 77e2cad088 content: Add new-in badge for usePackageJSON 0746e1e621 Add a page on using npm dependencies in Hugo Modules 8824850f5c Update HUGO_VERSION to 0.159.0 git-subtree-dir: docs git-subtree-split: 1f8ddb8a5230518f07c50b4b03cba3cae21081c4
5.7 KiB
title, linkTitle, description, categories, keywords, weight, aliases
| title | linkTitle | description | categories | keywords | weight | aliases | |
|---|---|---|---|---|---|---|---|
| Security model | Security | A summary of Hugo's security model. | 30 |
|
Security Boundaries
- The templates inside
layoutsare trusted. - The assets inside
archetypes,assets,resources,data,i18nandstaticare trusted. - The content and the content produced by content adapters inside
contentis not trusted. The one exception here is if inline shortcodes is enabled. Note that for content adapters, this is scoped to the result of the adapter. - The development server,
hugo server, and its livereload script is trusted and meant for local development only.
Runtime security
Hugo generates static websites, meaning the final output runs directly in the browser and interacts with any integrated APIs. However, during development and site building, the hugo executable itself is the runtime environment.
Securing a runtime is a complex task. Hugo addresses this through a robust sandboxing approach and a strict security policy with default protections. Key features include:
- Virtual file system: Hugo employs a virtual file system, limiting file access. Only the main project, not external components, can access files or directories outside the project root.
- Read-Only access: User-defined components have read-only access to the file system, preventing unintended modifications.
- Controlled external binaries: While Hugo utilizes external binaries for features like Asciidoctor support, these are strictly predefined with specific flags and are disabled by default. The security policy details these limitations.
- No arbitrary commands: To mitigate risks, Hugo intentionally avoids implementing general functions that would allow users to execute arbitrary operating system commands.
- Pragmatic defaults: The default security policy aims to balance security and usability, enabling common workflows out of the box while keeping more sensitive capabilities opt-in. These defaults may be tightened in future releases, but each project is ultimately responsible for reviewing the policy and adjusting it to match its own trust model and requirements.
This combination of sandboxing and strict defaults effectively minimizes potential security vulnerabilities during the Hugo build process.
Dependency security
Hugo utilizes Go Modules to manage its dependencies, compiling as a static binary. Go Modules create a go.sum file, a critical security feature. This file acts as a database, storing the expected cryptographic checksums of all dependencies, including those required indirectly (transitive dependencies).
Hugo Modules, which extend Go Modules' functionality, also produce a go.sum file. To ensure dependency integrity, commit this go.sum file to your version control. If Hugo detects a checksum mismatch during the build process, it will fail, indicating a possible attempt to tamper with your project's dependencies.
Web application security
Hugo's security philosophy is rooted in established security standards, primarily aligning with the threats defined by OWASP. For HTML output, Hugo operates under a clear trust model. This model assumes that template and configuration authors, the developers, are trustworthy. However, the data supplied to these templates is inherently considered untrusted. This distinction is crucial for understanding how Hugo handles potential security risks.
To prevent unintended escaping of data that developers know is safe, Hugo provides safe functions, such as safeHTML. These functions allow developers to explicitly mark data as trusted, bypassing the default escaping mechanisms. This is essential for scenarios where data is generated or sourced from reliable sources. However, an exception exists: enabling inline shortcodes. By activating this feature, you are implicitly trusting the logic within the shortcodes and the data contained within your content files.
It's vital to remember that Hugo is a static site generator. This architectural choice significantly reduces the attack surface by eliminating the complexities and vulnerabilities associated with dynamic user input. Unlike dynamic websites, Hugo generates static HTML files, minimizing the risk of real-time attacks. Regarding content, Hugo's default Markdown renderer is configured to sanitize potentially unsafe content. This default behavior ensures that potentially malicious code or scripts are removed or escaped. However, this setting can be reconfigured if you have a high degree of confidence in the safety of your content sources.
In essence, Hugo prioritizes secure output by establishing a clear trust boundary between developers and data. By default, it errs on the side of caution, sanitizing potentially unsafe content and escaping data. Developers have the flexibility to adjust these defaults through safe functions and configuration options, but they must do so with a clear understanding of the security implications. Hugo's static site generation model further strengthens its security posture by minimizing dynamic vulnerabilities.
Configuration
See configure security.