Skip to content

fix: validate the actual host of source repository URLs - #479

Open
ClarenceStark wants to merge 1 commit into
oss-compass:mainfrom
ClarenceStark:codex/fix-source-repository-url-validation
Open

ClarenceStark wants to merge 1 commit into
oss-compass:mainfrom
ClarenceStark:codex/fix-source-repository-url-validation

Conversation

@ClarenceStark

Copy link
Copy Markdown

The source URL validator shared by the sandbox, hatch, and graduation application forms accepts unrelated sites whenever github.com, gitee.com, or gitcode.com appears anywhere in the input. For example, https://example.org/github.com/owner/repo passes. It also rejects valid mixed-case hostnames.

Parse the URL and validate its HTTP(S) scheme, exact supported hostname, and owner/repository path. This is form validation, not a server-side security boundary.

Validation: Node 22.12.0 / Jest, src/modules/oh/utils/form.test.ts: baseline 10 failures; fixed 17 passing cases. Covers supported hosts, mixed-case hosts, misleading host/path/query/userinfo strings, missing repository paths, and unchanged commit SHA validation. Full form submission/backend integration was not run.

AI-assisted implementation and tests.

@vercel

vercel Bot commented Oct 4, 2026

Copy link
Copy Markdown

@ClarenceStark is attempting to deploy a commit to the codersett's projects Team on Vercel.

A member of the Team first needs to authorize it.

Signed-off-by: 曾泽梓 <3038736583@qq.com>
@ClarenceStark
ClarenceStark force-pushed the codex/fix-source-repository-url-validation branch from 6782bd2 to fb2dffa Compare October 5, 2026 03:12

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant