fix: SSRF-haertung (IP-pinning) + blank-page-schutz aus security-review
- scan & releases/from-url: verbindung wird an die bereits validierte IP gepinnt (node:http/https lookup-option), statt fetch erneut aufloesen zu lassen. Schliesst DNS-rebinding/TOCTOU, mit dem ein lizenzierter Kunde ueber die DNS seiner eigenen Domain interne Dienste/Cloud-Metadaten erreichen koennte. - releases/from-url folgt redirects jetzt manuell und validiert jeden hop (protokoll + private-IP-guard); gitea-token nur an den ausgangs-host. - pinnedRequest: settle-guard + body-cap loesen das promise auch bei ueberlangen antworten (kein haengen). - autodetect process(): kein blank-page mehr bei PCRE-fehler (fallback auf original-HTML statt (string) null = ""). - cleanup: ungenutztes extract_iframe_src() entfernt; redundantes &-replace in get_src() entfernt (DOMDocument dekodiert bereits). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -288,11 +288,6 @@ class CB_Renderer {
|
||||
. '</div>';
|
||||
}
|
||||
|
||||
/** Pull the src attribute out of an iframe string. */
|
||||
public static function extract_iframe_src( string $html ): string {
|
||||
return self::extract_iframe_attrs( $html )['src'];
|
||||
}
|
||||
|
||||
/**
|
||||
* Pull src + width + height out of an iframe string.
|
||||
* Height is also read from an inline style="height:NNNpx" if no attribute.
|
||||
|
||||
Reference in New Issue
Block a user