mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-09 17:36:15 -08:00
refactor(pwa): make stalker cmd append visibly query-only for CodeQL
Rebuild the /stalker request URL through the URL object and concatenate the encoded cmd strictly behind a literal '?', so static analysis can see the tainted value never reaches host or path (js/request-forgery alert on the previous separator ternary). Behavior unchanged; the fragment/bare-'?' regression tests still pin the wire format. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
e0617e1642
commit
b16ede9fbe
1 file changed
+13
-9
@@ -239,15 +239,19 @@ export function createWebBackendApp(
|
||||
const { cmd, ...proxyParams } = getProxyParams(req, ['targetId']);
|
||||
const portalUrl = new URL(url.href);
|
||||
portalUrl.hash = '';
|
||||
let requestUrl = portalUrl.href;
|
||||
if (cmd) {
|
||||
const separator = requestUrl.endsWith('?')
|
||||
? ''
|
||||
: portalUrl.search
|
||||
? '&'
|
||||
: '?';
|
||||
requestUrl = `${requestUrl}${separator}cmd=${encodeStalkerCmdValue(cmd)}`;
|
||||
}
|
||||
const registeredQuery = portalUrl.search.replace(/^\?/, '');
|
||||
portalUrl.search = '';
|
||||
const query = [
|
||||
registeredQuery,
|
||||
cmd ? `cmd=${encodeStalkerCmdValue(cmd)}` : '',
|
||||
]
|
||||
.filter(Boolean)
|
||||
.join('&');
|
||||
// cmd is appended strictly behind the literal `?`, so it can only
|
||||
// ever form query content — never host or path.
|
||||
const requestUrl = query
|
||||
? `${portalUrl.href}?${query}`
|
||||
: portalUrl.href;
|
||||
|
||||
// Provider URLs are validated by /provider-targets before they enter the registry.
|
||||
// codeql[js/request-forgery]
|
||||
|
||||
Reference in new issue
Block a user