Skip to content

fix(security): treat a slashless http: value as a remote authority - #1249

Merged
mrbobbytables merged 1 commit into
mainfrom
sec/fix-http-scheme-authority
Oct 10, 2026
Merged

mrbobbytables merged 1 commit into
mainfrom
sec/fix-http-scheme-authority

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Security Fix

Closes #1248

remoteTarget() (scripts/lib/uri-safety.mjs) is the one place this repository
decides whether a value makes a visitor's browser contact another host. It
recognised a remote value only when it found two or more separators, after an
optional https?: scheme:

const authority = normalized.replace(/^(https?:)?[/\\]{2,}/, …);
if (/^https?:\/\//.test(authority) || authority.startsWith('//')) {

That is correct for https:. The URL parser enters its relative states only
when the value's scheme equals the base document's, and the site is served
over https (url in docusaurus.config.js), so https:local.png and
https:/local.png really are paths on this origin — the existing suite already
pins that ("a scheme with a single separator").

http: is a different special scheme, so it never reaches those states. It
goes to "special authority ignore slashes", which skips however many / or \
follow — including none — and reads the next component as the host.
Verified against the WHATWG URL parser, base
https://endusers.cncf.io/architectures/demo/:

value browser resolves to remoteTarget() before
http:evil.example/b.png http://evil.example/b.png null
http:/evil.example/b.png http://evil.example/b.png null
http:\evil.example/b.png http://evil.example/b.png null
http:///evil.example/b.png http://evil.example/b.png null

findRemoteReferences() is what stops a published SVG hot-linking a third
party, and it is applied in mirrorArtworkUrls() before a mirrored
cncf/artwork SVG is written into static/, and again by
validate-architecture-assets.mjs over the asset tree. Both returned zero
findings
for <image href="http:evil.example/beacon.png"> and for
fill:url(http:evil.example/b.png), so such an asset published at the site
origin and disclosed every visitor's IP, User-Agent and Referer. Cleartext does
not neutralise that: a browser that auto-upgrades the mixed-content request
still sends it to the named host.

What changed

  • scripts/lib/uri-safety.mjs — remoteTarget() handles an http: value
    ahead of the // test, mirroring the parser. The lookahead
    (?=[^/\\?#]) keeps http:, http:/, http:?q and http:#f unflagged:
    none names a host, so none fetches anything. https: behaviour is untouched.
  • tests/svg-active-content.test.mjs — 10 regression tests through
    findRemoteReferences(): the slashless, single-slash, backslash, three-slash
    and uppercase forms, the CSS url() path, and four negative cases pinning
    that https:a.png and host-less http: values stay unflagged.

Verification

  • node --test tests/svg-active-content.test.mjs — 133/133 pass.
  • npm run validate:architectures — Validated 8 architecture records.
  • npm run validate:architecture-assets — Validated 172 architecture asset(s),
    unchanged before and after, so no asset in the repository regresses (the one
    foreignObject warning is pre-existing on main).
  • Full coverage gate (--check 99 --check-source 100 --check-regions 95 --check-source-regions 99 --check-source-file-regions 97 --require-source-files) exits 0; scripts/lib/uri-safety.mjs is
    100.00% lines / 100.00% regions.
  • npx prettier --check on both files — clean.

Files/functions claimed by this PR: scripts/lib/uri-safety.mjs
(remoteTarget) and tests/svg-active-content.test.mjs. Checked disjoint from
the only other open hold-gated PR, #1242, which touches
scripts/lib/architecture-pages.mjs, scripts/validate-architectures.mjs and
tests/architecture-pages.test.mjs.


Hold-gated: human review required.

— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88

remoteTarget() only recognised a remote value when it found two or more
separators, which is right for https: -- the scheme the site is served
over, where the URL parser goes relative -- but wrong for http:. A
different special scheme sends the parser to "special authority ignore
slashes", which skips however many separators follow, including none, and
reads the next component as the host. http:evil.example/b.png therefore
loaded from evil.example while findRemoteReferences() reported nothing,
so a mirrored or imported SVG could beacon every visitor past the gate.

Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
@hivecommons-hive hivecommons-hive Bot added the hold label Oct 9, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hold security Approved by a Hive merger/owner for auto-merge on green CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] remoteTarget() misses slashless http: authorities: http:evil.example/x publishes a third-party beacon past findRemoteReferences

1 participant