Skip to content

Potential fix for code scanning alert no. 12: Server-side request forgery - #97

Draft
moderniselife wants to merge 1 commit into
mainfrom
alert-autofix-12
Draft

moderniselife wants to merge 1 commit into
mainfrom
alert-autofix-12

Conversation

@moderniselife

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/moderniselife/SchroDrive/security/code-scanning/12

To fix this without changing intended behavior, keep accepting http/https torrent URLs but add defense-in-depth on the actual HTTP client call in src/providers/registry.ts:

  1. Parse and normalize the URL with new URL(...) after validation.
  2. Use the normalized URL string in axios.get.
  3. Disable automatic redirects (maxRedirects: 0) so a public URL cannot bounce to internal/private targets.
  4. Keep existing timeout and IPv4 agent behavior.

This is the safest minimal change in the shown code region and addresses both alert variants because they converge on the same sink (addTorrentFileFromUrl line 243 path).
Edit only src/providers/registry.ts in the addTorrentFileFromUrl method around lines 242–248.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…gery

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant