Skip to content

Parse and sanitize URL before sending it to open::that - #90

Merged
core1024 merged 1 commit into
mainfrom
no-rce
Jul 27, 2026
Merged

Parse and sanitize URL before sending it to open::that#90
core1024 merged 1 commit into
mainfrom
no-rce

Conversation

@core1024

@core1024 core1024 commented Jul 27, 2026

Copy link
Copy Markdown
Member

Moved the webview constants to the global constants file and added a safe_url helper function to parse an URL, validate it and escape it. This function is used everywhere for open::that sanitization.

@core1024
core1024 requested review from Ivshti, jaruba and tymmesyde July 27, 2026 13:36
@core1024
core1024 merged commit adfa9ab into main Jul 27, 2026
2 checks passed
@core1024
core1024 deleted the no-rce branch July 27, 2026 13:59
@kKaskak kKaskak added this to the v5.0.24 milestone Jul 27, 2026
@kKaskak kKaskak added the bug Something isn't working label Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants