Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug] useSignupForm.ts: communityWebsite regex allows IP addresses and internal hostnames to pass validation before https:// is prepended

Open
#131 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
typescript

Research direction

Start in src/features/Auth/v1/hooks/useSignupForm.ts at the communityWebsite field in signupSchema, and trace where its transformed value is consumed. Reproduce the listed IP-like and internal-hostname inputs, then verify that only safe HTTP(S) website values are accepted and private-range targets are rejected.

Written by the indexing model from the issue text.

Description

Bug Summary

The communityWebsite field in signupSchema validates that the user input does not include http:// or https://, then prepends https:// in a .transform():

communityWebsite: z
  .string()
  .optional()
  .or(z.literal(""))
  .refine(
    (val) => !val || /^(?!https?:\/\/)([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,}(\/.*)?$/.test(val),
    { message: "Enter domain only (e.g. example.com)." }
  )
  .transform((val) => (val && val.trim() !== "" ? `https://${val}` : val)),

The regex ([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,} accepts:

  1. IP addresses with appended labels: 192.168.1.internal or 169.254.169.metadata pass the regex (the part before the dot is valid, and internal/metadata are valid TLD-like strings).
  2. Internal hostnames: my-server.local or admin.lan pass the regex and are transformed to https://my-server.local and https://admin.lan.
  3. Subdomains of attacker-controlled domains: internal.attacker.com trivially passes.

After .transform(), the result https://192.168.1.internal is stored as the community website. If the backend later fetches the URL for a preview (link unfurling) or renders it as a clickable link, internal network addresses could reach backend services.

Additionally, the regex requires at minimum [a-zA-Z]{2,} after the final dot, which accepts single-character country codes and invented TLDs not in any public suffix list. There is no allowlist of known TLDs.

Expected Behavior

After prepending https://, the resulting URL should be additionally validated against a safe URL allowlist (only http: and https: schemes, no private IP ranges). A simple check using new URL(transformed) and verifying hostname does not resolve to a private range would catch most cases.

Actual Behavior

Internal hostnames and IP-like addresses pass the communityWebsite regex and are stored with https:// prepended.

Affected File

src/features/Auth/v1/hooks/useSignupForm.ts, communityWebsite field.


@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.

Dominant language
TypeScript
Stars
7
Forks
17
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NexGenStudioDev/CommDesk

All issues in NexGenStudioDev/CommDesk

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.