Skip to content

fix(desktop): validate openExternal URLs by protocol - #36862

Open
ulises-jeremias wants to merge 1 commit into
anomalyco:devfrom
ulises-jeremias:fix/desktop-open-link-protocol-validation-v2
Open

fix(desktop): validate openExternal URLs by protocol#36862
ulises-jeremias wants to merge 1 commit into
anomalyco:devfrom
ulises-jeremias:fix/desktop-open-link-protocol-validation-v2

Conversation

@ulises-jeremias

@ulises-jeremias ulises-jeremias commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Issue for this PR

Closes #30613

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

shell.openExternal accepts any URL without validation, allowing potentially dangerous protocols like file://, javascript:, and smb:. This adds an isSafeExternalLink() guard that restricts open-link IPC calls to http: and https: URLs only, with dedicated helper module for testability.

How did you verify your code works?

  • bun test src/main/external-link.test.ts — 3 tests pass covering allowed protocols, blocked protocols, and malformed URLs
  • bun typecheck (desktop package) — clean

Screenshots / recordings

N/A (no UI changes)

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

shell.openExternal accepts any URL without validation, allowing
potentially dangerous protocols like file://, javascript:, and smb:.
This adds an isSafeExternalLink() guard that restricts open-link
IPC calls to http: and https: URLs only.

Closes anomalyco#30613
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(desktop): shell.openExternal called without URL protocol validation

1 participant