Fix unvalidated URL redirection in HTTP redirects

Use baseurl.Parse to construct the HTTPS redirect URL in the
trust center HTTP handler, breaking the taint chain from raw
request headers. Apply path.Clean to the slug-based redirect
in stripTrustPrefix to normalize path traversal sequences.

Addresses CodeQL go/unvalidated-url-redirection (CWE-601).

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-03-19 14:54:53 +01:00
parent c74e5cc123
commit 8ed6f1824f
2 changed files with 10 additions and 2 deletions

View File

@@ -767,7 +767,13 @@ func newTrustCenterHTTPRedirectHandler(proboService *probo.Service, l *log.Logge
}
// This is a trust center domain, redirect to HTTPS
httpsURL := "https://" + r.Host + r.URL.RequestURI()
base, err := baseurl.Parse("https://" + domain)
if err != nil {
httpserver.RenderError(w, http.StatusNotFound, errors.New("not found"))
return
}
httpsURL := base.WithPath(r.URL.Path).WithQueryValues(r.URL.Query()).MustString()
l.InfoCtx(
ctx,
"HTTP request to trust center custom domain, redirecting to HTTPS",

View File

@@ -17,6 +17,7 @@ package server
import (
"errors"
"net/http"
"path"
"strings"
"github.com/go-chi/chi/v5"
@@ -156,7 +157,8 @@ func (s *Server) stripTrustPrefix(next http.Handler) http.Handler {
prefix := "/trust/" + slugOrId
if r.URL.Path == prefix {
http.Redirect(w, r, prefix+"/", http.StatusMovedPermanently)
cleanPath := path.Clean(prefix) + "/"
http.Redirect(w, r, cleanPath, http.StatusMovedPermanently)
return
}