Fix unvalidated URL redirection in HTTP redirects
Use baseurl.Parse to construct the HTTPS redirect URL in the trust center HTTP handler, breaking the taint chain from raw request headers. Apply path.Clean to the slug-based redirect in stripTrustPrefix to normalize path traversal sequences. Addresses CodeQL go/unvalidated-url-redirection (CWE-601). Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -767,7 +767,13 @@ func newTrustCenterHTTPRedirectHandler(proboService *probo.Service, l *log.Logge
|
||||
}
|
||||
|
||||
// This is a trust center domain, redirect to HTTPS
|
||||
httpsURL := "https://" + r.Host + r.URL.RequestURI()
|
||||
base, err := baseurl.Parse("https://" + domain)
|
||||
if err != nil {
|
||||
httpserver.RenderError(w, http.StatusNotFound, errors.New("not found"))
|
||||
return
|
||||
}
|
||||
|
||||
httpsURL := base.WithPath(r.URL.Path).WithQueryValues(r.URL.Query()).MustString()
|
||||
l.InfoCtx(
|
||||
ctx,
|
||||
"HTTP request to trust center custom domain, redirecting to HTTPS",
|
||||
|
||||
@@ -17,6 +17,7 @@ package server
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
"path"
|
||||
"strings"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
@@ -156,7 +157,8 @@ func (s *Server) stripTrustPrefix(next http.Handler) http.Handler {
|
||||
prefix := "/trust/" + slugOrId
|
||||
|
||||
if r.URL.Path == prefix {
|
||||
http.Redirect(w, r, prefix+"/", http.StatusMovedPermanently)
|
||||
cleanPath := path.Clean(prefix) + "/"
|
||||
http.Redirect(w, r, cleanPath, http.StatusMovedPermanently)
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user