From aa590fcd9a4583f6b144ef292ed6ca3966a60f41 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Fri, 11 Jul 2025 17:56:26 +0800 Subject: [PATCH] Improve host validation for download link detection Refactored isDownloadLink to use URL parsing for host checks on GitHub and Hugging Face links, improving accuracy and robustness. Added error handling for invalid URLs and clarified host-specific download patterns. --- content.js | 63 +++++++++++++++++++++++++++++++++--------------------- 1 file changed, 39 insertions(+), 24 deletions(-) diff --git a/content.js b/content.js index 65ceade..871cf1d 100644 --- a/content.js +++ b/content.js @@ -158,26 +158,32 @@ function isDownloadLink(link) { } // Third check: GitHub-specific patterns - if (href.includes("github.com")) { - // GitHub release asset download URLs follow pattern: /releases/download/ - if (pathname.includes("/releases/download/")) { - return true; - } - // GitHub archive download URLs - if ( - pathname.includes("/archive/") && - (pathname.endsWith(".zip") || pathname.endsWith(".tar.gz")) - ) { - return true; - } - // GitHub raw file URLs - NEW: support for raw file links - if (pathname.includes("/raw/")) { - return true; - } - // Exclude navigation to releases page (just /releases or /releases/) - if (pathname.endsWith("/releases") || pathname.endsWith("/releases/")) { - return false; + const allowedGitHubHosts = ["github.com"]; + try { + const parsedUrl = new URL(href); + if (allowedGitHubHosts.includes(parsedUrl.host)) { + // GitHub release asset download URLs follow pattern: /releases/download/ + if (pathname.includes("/releases/download/")) { + return true; + } + // GitHub archive download URLs + if ( + pathname.includes("/archive/") && + (pathname.endsWith(".zip") || pathname.endsWith(".tar.gz")) + ) { + return true; + } + // GitHub raw file URLs - NEW: support for raw file links + if (pathname.includes("/raw/")) { + return true; + } + // Exclude navigation to releases page (just /releases or /releases/) + if (pathname.endsWith("/releases") || pathname.endsWith("/releases/")) { + return false; + } } + } catch (e) { + console.error("Invalid URL:", href, e); } // Fourth check: GitLab-specific patterns @@ -190,7 +196,10 @@ function isDownloadLink(link) { return true; } // GitLab release downloads - if (pathname.includes("/-/releases/") && pathname.includes("/downloads/")) { + if ( + pathname.includes("/-/releases/") && + pathname.includes("/downloads/") + ) { return true; } } @@ -199,11 +208,17 @@ function isDownloadLink(link) { } // Fifth check: Hugging Face file downloads - if (href.includes("huggingface.co")) { - // HF file download URLs contain /resolve/ - if (pathname.includes("/resolve/")) { - return true; + const allowedHuggingFaceHosts = ["huggingface.co"]; + try { + const parsedUrl = new URL(href); + if (allowedHuggingFaceHosts.includes(parsedUrl.host)) { + // HF file download URLs contain /resolve/ + if (pathname.includes("/resolve/")) { + return true; + } } + } catch (e) { + console.error("Invalid URL:", href, e); } // Seventh check: explicit download text indicators (be more specific)