From 90c676481d4ecba9df8fca3ff3c40d7e04166a18 Mon Sep 17 00:00:00 2001 From: DrMelone <27028174+Classic298@users.noreply.github.com> Date: Fri, 3 Apr 2026 22:35:29 +0200 Subject: [PATCH] fix: validate hostname not netloc, fix misleading comment - Use parsed.hostname instead of parsed.netloc so URLs like http://:80/path (non-empty netloc but no actual host) are rejected. - Update data URI comment to accurately state we validate MIME type and structure, not base64 payload integrity. --- backend/open_webui/utils/validate.py | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/backend/open_webui/utils/validate.py b/backend/open_webui/utils/validate.py index f2aed7bb5d..98e03d9166 100644 --- a/backend/open_webui/utils/validate.py +++ b/backend/open_webui/utils/validate.py @@ -3,7 +3,8 @@ import re from urllib.parse import urlparse -# Matches well-formed base64 data URIs for safe raster image formats. +# Validates the MIME type and structure of base64 data URIs, not payload +# integrity — corrupt base64 simply produces a broken image, same as a 404 URL. # SVG is intentionally excluded: it can carry embedded scripts. _SAFE_DATA_URI_RE = re.compile( r'^data:image/(png|jpeg|gif|webp);base64,', re.IGNORECASE @@ -38,9 +39,10 @@ def validate_profile_image_url(url: str) -> str: parsed = urlparse(url) # External images served over HTTP(S), e.g. OAuth provider avatars. - # Require a non-empty netloc so bare "https://" is rejected. + # Require a non-empty hostname (not just netloc, which can be ":80" + # for a URL like http://:80/path with no actual host). if parsed.scheme in ('http', 'https'): - if not parsed.netloc: + if not parsed.hostname: raise ValueError( 'Invalid profile image URL: HTTP(S) URLs must include a host.' )