fix(config): reject WebSocket URL fragments at parse boundary

This commit is contained in:
2026-09-05 21:27:29 +08:00
parent 053302c5df
commit 58c974e114
2 changed files with 9 additions and 1 deletions
@@ -69,7 +69,7 @@ function normalizeWebSocketUrl(value: string): string {
}
try {
const parsed = new URL(url);
if (!value || /\s/.test(value) || !parsed.hostname || parsed.username || parsed.password
if (!value || /\s/.test(value) || url.includes('#') || !parsed.hostname || parsed.username || parsed.password
|| (parsed.protocol !== 'ws:' && parsed.protocol !== 'wss:')) throw new Error('invalid');
} catch {
throw new ConfigParseError('Invalid remote server: malformed WebSocket URL');
@@ -66,3 +66,11 @@ test('missing or invalid chosen servers never fall back to obsolete envelope or
assert.throws(() => api.parseUrlServers(view(raw)), api.ConfigParseError);
}
});
test('WebSocket fragments including an empty trailing marker fail at the config boundary', () => {
for (const address of ['ws://127.0.0.1:3088/#invalid', 'wss://example.test/#', 'example.test:3088#']) {
assert.throws(() => api.parseUrlServers(view({ player_server_tcp: address })), api.ConfigParseError);
}
assert.deepEqual(api.parseUrlServers(view({ player_server_tcp: 'wss://example.test/path%23part' })),
['wss://example.test/path%23part']);
});