Repository navigation
fix(security): treat a slashless http: value as a remote authority - #1249
Merged
Merged
Conversation
remoteTarget() only recognised a remote value when it found two or more separators, which is right for https: -- the scheme the site is served over, where the URL parser goes relative -- but wrong for http:. A different special scheme sends the parser to "special authority ignore slashes", which skips however many separators follow, including none, and reads the next component as the host. http:evil.example/b.png therefore loaded from evil.example while findRemoteReferences() reported nothing, so a mirrored or imported SVG could beacon every visitor past the gate. Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
Closes #1248
remoteTarget()(scripts/lib/uri-safety.mjs) is the one place this repositorydecides whether a value makes a visitor's browser contact another host. It
recognised a remote value only when it found two or more separators, after an
optional
https?:scheme:That is correct for
https:. The URL parser enters its relative states onlywhen the value's scheme equals the base document's, and the site is served
over https (
urlindocusaurus.config.js), sohttps:local.pngandhttps:/local.pngreally are paths on this origin — the existing suite alreadypins that ("a scheme with a single separator").
http:is a different special scheme, so it never reaches those states. Itgoes to "special authority ignore slashes", which skips however many
/or\follow — including none — and reads the next component as the host.
Verified against the WHATWG URL parser, base
https://endusers.cncf.io/architectures/demo/:remoteTarget()beforehttp:evil.example/b.pnghttp://evil.example/b.pngnullhttp:/evil.example/b.pnghttp://evil.example/b.pngnullhttp:\evil.example/b.pnghttp://evil.example/b.pngnullhttp:///evil.example/b.pnghttp://evil.example/b.pngnullfindRemoteReferences()is what stops a published SVG hot-linking a thirdparty, and it is applied in
mirrorArtworkUrls()before a mirroredcncf/artwork SVG is written into
static/, and again byvalidate-architecture-assets.mjsover the asset tree. Both returned zerofindings for
<image href="http:evil.example/beacon.png">and forfill:url(http:evil.example/b.png), so such an asset published at the siteorigin and disclosed every visitor's IP, User-Agent and Referer. Cleartext does
not neutralise that: a browser that auto-upgrades the mixed-content request
still sends it to the named host.
What changed
scripts/lib/uri-safety.mjs—remoteTarget()handles anhttp:valueahead of the
//test, mirroring the parser. The lookahead(?=[^/\\?#])keepshttp:,http:/,http:?qandhttp:#funflagged:none names a host, so none fetches anything.
https:behaviour is untouched.tests/svg-active-content.test.mjs— 10 regression tests throughfindRemoteReferences(): the slashless, single-slash, backslash, three-slashand uppercase forms, the CSS
url()path, and four negative cases pinningthat
https:a.pngand host-lesshttp:values stay unflagged.Verification
node --test tests/svg-active-content.test.mjs— 133/133 pass.npm run validate:architectures—Validated 8 architecture records.npm run validate:architecture-assets—Validated 172 architecture asset(s),unchanged before and after, so no asset in the repository regresses (the one
foreignObjectwarning is pre-existing onmain).--check 99 --check-source 100 --check-regions 95 --check-source-regions 99 --check-source-file-regions 97 --require-source-files) exits 0;scripts/lib/uri-safety.mjsis100.00% lines / 100.00% regions.
npx prettier --checkon both files — clean.Files/functions claimed by this PR:
scripts/lib/uri-safety.mjs(
remoteTarget) andtests/svg-active-content.test.mjs. Checked disjoint fromthe only other open hold-gated PR, #1242, which touches
scripts/lib/architecture-pages.mjs,scripts/validate-architectures.mjsandtests/architecture-pages.test.mjs.Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88