[Bug] useSignupForm.ts: communityWebsite regex allows IP addresses and internal hostnames to pass validation before https:// is prepended
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- authentication, security
Research direction
Start in src/features/Auth/v1/hooks/useSignupForm.ts at the communityWebsite field in signupSchema, and trace where its transformed value is consumed. Reproduce the listed IP-like and internal-hostname inputs, then verify that only safe HTTP(S) website values are accepted and private-range targets are rejected.
Written by the indexing model from the issue text.
Description
Bug Summary
The communityWebsite field in signupSchema validates that the user input does not include http:// or https://, then prepends https:// in a .transform():
communityWebsite: z
.string()
.optional()
.or(z.literal(""))
.refine(
(val) => !val || /^(?!https?:\/\/)([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,}(\/.*)?$/.test(val),
{ message: "Enter domain only (e.g. example.com)." }
)
.transform((val) => (val && val.trim() !== "" ? `https://${val}` : val)),
The regex ([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,} accepts:
- IP addresses with appended labels:
192.168.1.internalor169.254.169.metadatapass the regex (the part before the dot is valid, andinternal/metadataare valid TLD-like strings). - Internal hostnames:
my-server.localoradmin.lanpass the regex and are transformed tohttps://my-server.localandhttps://admin.lan. - Subdomains of attacker-controlled domains:
internal.attacker.comtrivially passes.
After .transform(), the result https://192.168.1.internal is stored as the community website. If the backend later fetches the URL for a preview (link unfurling) or renders it as a clickable link, internal network addresses could reach backend services.
Additionally, the regex requires at minimum [a-zA-Z]{2,} after the final dot, which accepts single-character country codes and invented TLDs not in any public suffix list. There is no allowlist of known TLDs.
Expected Behavior
After prepending https://, the resulting URL should be additionally validated against a safe URL allowlist (only http: and https: schemes, no private IP ranges). A simple check using new URL(transformed) and verifying hostname does not resolve to a private range would catch most cases.
Actual Behavior
Internal hostnames and IP-like addresses pass the communityWebsite regex and are stored with https:// prepended.
Affected File
src/features/Auth/v1/hooks/useSignupForm.ts, communityWebsite field.
@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.
- Dominant language
- TypeScript
- Stars
- 7
- Forks
- 17
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NexGenStudioDev/CommDesk
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
NexGenStudioDev/CommDesk#140 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
NexGenStudioDev/CommDesk#138 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
NexGenStudioDev/CommDesk#130 · 2 comments ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NexGenStudioDev/CommDesk#123 · 2 comments ·
-
[UX] Hardcoded window dimensions not DPI-aware — UI broken on high-DPI displaysPossibly taken @anshul23102 claimed this 89 days ago. Open
NexGenStudioDev/CommDesk#141 · 1 assignee ·
All issues in NexGenStudioDev/CommDesk
Similar issues
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated oneOpendata-lake
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
enhancement good first issue priority: low size: XS
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
bug ios mobile priority:P1
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
streamplace/streamplace#1351 ·
Maintainers usually reply within 2 days