Media URL traversal check (integrations 0.2.1) + image alt text (ui 0.5.0) - #8
Merged
Merged
Conversation
`clean_media_url` checked the raw string, so percent-encoded (`%2e%2e`), double-encoded (`%252e%252e`) and backslash-based (`a\..\b`) dot segments passed the ".." substring check even though browsers resolve them as traversal once decoded — letting an admin-authored <img src> trigger a same-origin GET against arbitrary paths. Now the decoded, normalised path is validated to stay inside /media/. Bump basicbar-integrations to 0.2.1 and add a CHANGELOG entry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
After a successful image upload (toolbar, paste, or drop), prompt for alt text and insert the image with it (empty/cancelled -> alt=""). A new toolbar button lets authors re-open the prompt for the currently selected image, prefilled with its current alt. Also set shouldRerenderOnTransaction: true on useEditor -- TipTap 3 no longer re-renders on selection-only changes by default, which left every isActive()-driven toolbar button (not just the new one) stale after clicking around without editing. Bump @basicbar/ui to 0.5.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…th media URLs (#6) Round 1 review found further bypasses the WHATWG URL parser resolves but the previous string check didn't catch: raw or percent-encoded C0/DEL control characters (e.g. a tab hidden inside a "..") that browsers strip before resolving; a "?"/"#" (raw or encoded) hiding a trailing ".." from the substring check; and validating a long path before truncating it to 300 chars, which could cut it back down into a traversal. All three are now rejected outright, checked on both the raw and decoded URL. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… selected (#7) Use aria-disabled with a no-op click instead of native disabled, and do not render aria-disabled="false" on enabled toolbar buttons. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #6
Closes #7
integrations 0.2.1 —
clean_media_url(#6)The check now looks at the decoded, normalised path, which has to stay inside
/media/. The following are rejected:%2e%2e) and double encoding (%252e)//?/#Valid URLs come back unchanged, including
%20,%C3%BCand names likea..b.png.ui 0.5.0 — image alt text in
RichTextEditor(#7)alt="", meaning the image is decorative.aria-disabledbut still focusable.onUploadImageis set.shouldRerenderOnTransaction: truefixes stale active states in the toolbar under TipTap v3. That bug already existed in 0.4.0.Tests
?/#, over-length URLs and double encoding.npm run buildpasses. Browser check in Ausleihbar with the packed tgz: alt text after upload, editing via the button, and the button stays focusable with no effect when no image is selected.Release after merge
Tags
integrations/v0.2.1andui/v0.5.0.🤖 Generated with Claude Code