mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-08 03:08:02 +00:00
fix: validate hostname not netloc, fix misleading comment
- Use parsed.hostname instead of parsed.netloc so URLs like http://:80/path (non-empty netloc but no actual host) are rejected. - Update data URI comment to accurately state we validate MIME type and structure, not base64 payload integrity.
This commit is contained in:
parent
3d579f23e0
commit
90c676481d
1 changed files with 5 additions and 3 deletions
|
|
@ -3,7 +3,8 @@
|
|||
import re
|
||||
from urllib.parse import urlparse
|
||||
|
||||
# Matches well-formed base64 data URIs for safe raster image formats.
|
||||
# Validates the MIME type and structure of base64 data URIs, not payload
|
||||
# integrity — corrupt base64 simply produces a broken image, same as a 404 URL.
|
||||
# SVG is intentionally excluded: it can carry embedded scripts.
|
||||
_SAFE_DATA_URI_RE = re.compile(
|
||||
r'^data:image/(png|jpeg|gif|webp);base64,', re.IGNORECASE
|
||||
|
|
@ -38,9 +39,10 @@ def validate_profile_image_url(url: str) -> str:
|
|||
parsed = urlparse(url)
|
||||
|
||||
# External images served over HTTP(S), e.g. OAuth provider avatars.
|
||||
# Require a non-empty netloc so bare "https://" is rejected.
|
||||
# Require a non-empty hostname (not just netloc, which can be ":80"
|
||||
# for a URL like http://:80/path with no actual host).
|
||||
if parsed.scheme in ('http', 'https'):
|
||||
if not parsed.netloc:
|
||||
if not parsed.hostname:
|
||||
raise ValueError(
|
||||
'Invalid profile image URL: HTTP(S) URLs must include a host.'
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue