-
Notifications
You must be signed in to change notification settings - Fork 1
Validate URLs before opening in url_opener #21
Copy link
Copy link
Open
Labels
enhancementNew feature or requestNew feature or requestsecuritySecurity hardeningSecurity hardeningv1.5.1Targeted for v1.5.1 releaseTargeted for v1.5.1 release
Description
Context
url_opener.open_url() passes its argument directly to XDG portal / xdg-open without scheme validation. A malformed PR URL from the API could open arbitrary schemes.
Task
Restrict to https:// (or http:///https://). Reject anything else.
Severity: HIGH
Source: Code review H2
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestsecuritySecurity hardeningSecurity hardeningv1.5.1Targeted for v1.5.1 releaseTargeted for v1.5.1 release