Restrict OAuth client branding URLs to http(s)

CIMD and registration accepted any URI scheme for client_uri and
logo_uri, so allowlisted metadata could surface javascript: links on
sign-in. Validate absolute http/https at ingest and only expose those
schemes in branding.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-07-17 14:01:25 +02:00
parent 6da00604ed
commit e7df6f6b2a
10 changed files with 322 additions and 17 deletions

View File

@@ -53,12 +53,14 @@ func ClientBrandingFromClient(client *coredata.OAuth2Client) *ClientBranding {
Name: client.ClientName,
}
if client.ClientURI != nil {
// Only expose absolute http(s) URLs. Metadata may historically contain
// non-web schemes; branding must not surface those as links or image src.
if client.ClientURI != nil && client.ClientURI.IsHTTP() {
clientURL := client.ClientURI.String()
branding.ClientURL = &clientURL
}
if client.LogoURI != nil {
if client.LogoURI != nil && client.LogoURI.IsHTTP() {
logoURL := client.LogoURI.String()
branding.LogoURL = &logoURL
}