fix(docs): constrain user runtime links
This commit is contained in:
@@ -681,7 +681,10 @@ def _bounded_string_list(value: object, *, maximum_items: int, maximum_length: i
|
||||
def _user_link_allowed(link: DocumentationLink) -> bool:
|
||||
href = link.href.strip()
|
||||
if link.kind == "runtime":
|
||||
return href.startswith("/") and not href.startswith("//")
|
||||
if not href.startswith("/") or href.startswith("//") or "\\" in href:
|
||||
return False
|
||||
parsed = urlsplit(href)
|
||||
return not parsed.scheme and not parsed.netloc
|
||||
if link.kind != "public":
|
||||
return False
|
||||
parsed = urlsplit(href)
|
||||
|
||||
@@ -102,6 +102,7 @@ class DocsContextTests(unittest.TestCase):
|
||||
links=(
|
||||
DocumentationLink(label="Open task", href="/example", kind="runtime"),
|
||||
DocumentationLink(label="Unsafe runtime", href="javascript:alert(1)", kind="runtime"),
|
||||
DocumentationLink(label="Backslash runtime", href="/\\evil.invalid", kind="runtime"),
|
||||
DocumentationLink(label="Public help", href="https://example.invalid/help", kind="public"),
|
||||
DocumentationLink(label="Repository", href="example/docs/SECRET.md", kind="repository"),
|
||||
DocumentationLink(label="API", href="/api/v1/example", kind="api"),
|
||||
|
||||
Reference in New Issue
Block a user