fix(config): reject WebSocket URL fragments at parse boundary
This commit is contained in:
@@ -69,7 +69,7 @@ function normalizeWebSocketUrl(value: string): string {
|
||||
}
|
||||
try {
|
||||
const parsed = new URL(url);
|
||||
if (!value || /\s/.test(value) || !parsed.hostname || parsed.username || parsed.password
|
||||
if (!value || /\s/.test(value) || url.includes('#') || !parsed.hostname || parsed.username || parsed.password
|
||||
|| (parsed.protocol !== 'ws:' && parsed.protocol !== 'wss:')) throw new Error('invalid');
|
||||
} catch {
|
||||
throw new ConfigParseError('Invalid remote server: malformed WebSocket URL');
|
||||
|
||||
Reference in New Issue
Block a user