fix(config): reject WebSocket URL fragments at parse boundary
This commit is contained in:
@@ -69,7 +69,7 @@ function normalizeWebSocketUrl(value: string): string {
|
|||||||
}
|
}
|
||||||
try {
|
try {
|
||||||
const parsed = new URL(url);
|
const parsed = new URL(url);
|
||||||
if (!value || /\s/.test(value) || !parsed.hostname || parsed.username || parsed.password
|
if (!value || /\s/.test(value) || url.includes('#') || !parsed.hostname || parsed.username || parsed.password
|
||||||
|| (parsed.protocol !== 'ws:' && parsed.protocol !== 'wss:')) throw new Error('invalid');
|
|| (parsed.protocol !== 'ws:' && parsed.protocol !== 'wss:')) throw new Error('invalid');
|
||||||
} catch {
|
} catch {
|
||||||
throw new ConfigParseError('Invalid remote server: malformed WebSocket URL');
|
throw new ConfigParseError('Invalid remote server: malformed WebSocket URL');
|
||||||
|
|||||||
@@ -66,3 +66,11 @@ test('missing or invalid chosen servers never fall back to obsolete envelope or
|
|||||||
assert.throws(() => api.parseUrlServers(view(raw)), api.ConfigParseError);
|
assert.throws(() => api.parseUrlServers(view(raw)), api.ConfigParseError);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test('WebSocket fragments including an empty trailing marker fail at the config boundary', () => {
|
||||||
|
for (const address of ['ws://127.0.0.1:3088/#invalid', 'wss://example.test/#', 'example.test:3088#']) {
|
||||||
|
assert.throws(() => api.parseUrlServers(view({ player_server_tcp: address })), api.ConfigParseError);
|
||||||
|
}
|
||||||
|
assert.deepEqual(api.parseUrlServers(view({ player_server_tcp: 'wss://example.test/path%23part' })),
|
||||||
|
['wss://example.test/path%23part']);
|
||||||
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user