Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(Update) don't match . with * using whitelisted image domain syntax #3961

Merged
merged 1 commit into from
Jul 4, 2024

Conversation

Roardom
Copy link
Collaborator

@Roardom Roardom commented Jul 3, 2024

It's too easy for sysops to add https://*imgur.com/** instead of properly adding https://*.imgur.com/** or even better, https://i.imgur.com/**. This makes it easier to spot errors in the syntax errored since the intended whitelisted domain won't work. Add some more documentation to encourage safe practices and add example evil URLs that are permitted by the bypass for visual feedback of what is allowed.

It's too easy for sysops to add `https://*imgur.com/**` instead of properly adding `https://*.imgur.com/**` or even better, `https://i.imgur.com/**`. This makes it easier to spot errors in the syntax errored since the intended whitelisted domain won't work. Add some more documentation to encourage safe practices and add example evil URLs that are permitted by the bypass for visual feedback of what is allowed.
@HDVinnie HDVinnie merged commit a590766 into HDInnovations:8.x.x Jul 4, 2024
5 checks passed
@HDVinnie HDVinnie deleted the safer-whitelisted-urls branch July 4, 2024 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants