fix(docs): constrain user runtime links
This commit is contained in:
@@ -681,7 +681,10 @@ def _bounded_string_list(value: object, *, maximum_items: int, maximum_length: i
|
|||||||
def _user_link_allowed(link: DocumentationLink) -> bool:
|
def _user_link_allowed(link: DocumentationLink) -> bool:
|
||||||
href = link.href.strip()
|
href = link.href.strip()
|
||||||
if link.kind == "runtime":
|
if link.kind == "runtime":
|
||||||
return href.startswith("/") and not href.startswith("//")
|
if not href.startswith("/") or href.startswith("//") or "\\" in href:
|
||||||
|
return False
|
||||||
|
parsed = urlsplit(href)
|
||||||
|
return not parsed.scheme and not parsed.netloc
|
||||||
if link.kind != "public":
|
if link.kind != "public":
|
||||||
return False
|
return False
|
||||||
parsed = urlsplit(href)
|
parsed = urlsplit(href)
|
||||||
|
|||||||
@@ -102,6 +102,7 @@ class DocsContextTests(unittest.TestCase):
|
|||||||
links=(
|
links=(
|
||||||
DocumentationLink(label="Open task", href="/example", kind="runtime"),
|
DocumentationLink(label="Open task", href="/example", kind="runtime"),
|
||||||
DocumentationLink(label="Unsafe runtime", href="javascript:alert(1)", kind="runtime"),
|
DocumentationLink(label="Unsafe runtime", href="javascript:alert(1)", kind="runtime"),
|
||||||
|
DocumentationLink(label="Backslash runtime", href="/\\evil.invalid", kind="runtime"),
|
||||||
DocumentationLink(label="Public help", href="https://example.invalid/help", kind="public"),
|
DocumentationLink(label="Public help", href="https://example.invalid/help", kind="public"),
|
||||||
DocumentationLink(label="Repository", href="example/docs/SECRET.md", kind="repository"),
|
DocumentationLink(label="Repository", href="example/docs/SECRET.md", kind="repository"),
|
||||||
DocumentationLink(label="API", href="/api/v1/example", kind="api"),
|
DocumentationLink(label="API", href="/api/v1/example", kind="api"),
|
||||||
|
|||||||
Reference in New Issue
Block a user