Potential fix for code scanning alert no. 3: Incomplete URL substring sanitization
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
1 parent
1bf90efe75
commit
b915e32b6b
1 file changed
+14
-8
+14
-8
@@ -181,15 +181,21 @@ function isDownloadLink(link) {
|
||||
}
|
||||
|
||||
// Fourth check: GitLab-specific patterns
|
||||
if (href.includes("gitlab.com")) {
|
||||
// GitLab archive downloads
|
||||
if (pathname.includes("/-/archive/")) {
|
||||
return true;
|
||||
}
|
||||
// GitLab release downloads
|
||||
if (pathname.includes("/-/releases/") && pathname.includes("/downloads/")) {
|
||||
return true;
|
||||
const allowedGitLabHosts = ["gitlab.com"];
|
||||
try {
|
||||
const parsedUrl = new URL(href);
|
||||
if (allowedGitLabHosts.includes(parsedUrl.host)) {
|
||||
// GitLab archive downloads
|
||||
if (pathname.includes("/-/archive/")) {
|
||||
return true;
|
||||
}
|
||||
// GitLab release downloads
|
||||
if (pathname.includes("/-/releases/") && pathname.includes("/downloads/")) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
} catch (e) {
|
||||
console.error("Invalid URL:", href, e);
|
||||
}
|
||||
|
||||
// Fifth check: Hugging Face file downloads
|
||||
|
||||
Reference in new issue
Block a user