Skip to content

Media URL traversal check (integrations 0.2.1) + image alt text (ui 0.5.0) - #8

Merged
rrolf merged 4 commits into
mainfrom
fix/media-url-alt-text
Sep 29, 2026
Merged

rrolf merged 4 commits into
mainfrom
fix/media-url-alt-text

Conversation

@rrolf

@rrolf rrolf commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Closes #6
Closes #7

integrations 0.2.1 — clean_media_url (#6)

The check now looks at the decoded, normalised path, which has to stay inside /media/. The following are rejected:

  • percent-encoded dot segments (%2e%2e) and double encoding (%252e)
  • backslashes and //
  • raw or encoded ? / #
  • C0 control characters and DEL (TAB/LF/CR in particular, because browsers strip them)
  • URLs longer than 300 characters. They are now rejected instead of truncated after validation.

Valid URLs come back unchanged, including %20, %C3%BC and names like a..b.png.

ui 0.5.0 — image alt text in RichTextEditor (#7)

  • After an upload, a prompt asks for "Image description (alt text)". Leaving it empty or cancelling gives alt="", meaning the image is decorative.
  • A new toolbar button "Image description" edits the alt text of the selected image. The prompt is prefilled, and Cancel leaves the alt text unchanged. When no image is selected the button is aria-disabled but still focusable.
  • The button is only shown when onUploadImage is set.
  • shouldRerenderOnTransaction: true fixes stale active states in the toolbar under TipTap v3. That bug already existed in 0.4.0.
  • The README lists the new i18n keys.

Tests

  • integrations: 57/57 pass, including edge-case probes for TAB/LF/CR, ?/#, over-length URLs and double encoding.
  • ui: npm run build passes. Browser check in Ausleihbar with the packed tgz: alt text after upload, editing via the button, and the button stays focusable with no effect when no image is selected.

Release after merge

Tags integrations/v0.2.1 and ui/v0.5.0.

🤖 Generated with Claude Code

rrolf and others added 4 commits September 28, 2026 09:01
`clean_media_url` checked the raw string, so percent-encoded (`%2e%2e`),
double-encoded (`%252e%252e`) and backslash-based (`a\..\b`) dot segments
passed the ".." substring check even though browsers resolve them as
traversal once decoded — letting an admin-authored <img src> trigger a
same-origin GET against arbitrary paths. Now the decoded, normalised path
is validated to stay inside /media/.

Bump basicbar-integrations to 0.2.1 and add a CHANGELOG entry.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
After a successful image upload (toolbar, paste, or drop), prompt for
alt text and insert the image with it (empty/cancelled -> alt=""). A
new toolbar button lets authors re-open the prompt for the currently
selected image, prefilled with its current alt.

Also set shouldRerenderOnTransaction: true on useEditor -- TipTap 3
no longer re-renders on selection-only changes by default, which left
every isActive()-driven toolbar button (not just the new one) stale
after clicking around without editing.

Bump @basicbar/ui to 0.5.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…th media URLs (#6)

Round 1 review found further bypasses the WHATWG URL parser resolves but
the previous string check didn't catch: raw or percent-encoded C0/DEL
control characters (e.g. a tab hidden inside a "..") that browsers strip
before resolving; a "?"/"#" (raw or encoded) hiding a trailing ".." from
the substring check; and validating a long path before truncating it to
300 chars, which could cut it back down into a traversal. All three are
now rejected outright, checked on both the raw and decoded URL.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… selected (#7)

Use aria-disabled with a no-op click instead of native disabled, and do not
render aria-disabled="false" on enabled toolbar buttons.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rrolf
rrolf merged commit 9653072 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RichTextEditor: Alternativtext für Bilder setzen können clean_media_url akzeptiert prozent-kodierte Punkt-Segmente (/media/%2e%2e/…)

1 participant