Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Navigation guard misses redirect hops to private addresses

オープン
#20 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript
領域
security

調査の方向性

Read the page.route('**/*') handler and the existing assertPublicUrl and isPublicHost checks; then find the tests for request routing. Add a test where a public URL redirects to a private address, and verify that the redirect is blocked before the browser follows it.

索引モデルが issue の本文から書いたものです。

説明

The SSRF guard from #18 checks the initial URL (assertPublicUrl) and every request seen by page.route('**/*'). Playwright only calls the route handler for the first URL in a redirect chain, so a public URL that redirects to a private or link-local address is followed without being checked.

Reproduction (appwrite/browser 0.3.5, Appwrite Cloud staging and production, 2026-10-04/05):

  • /v1/avatars/screenshots?url=https://httpbin.org/redirect-to?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F passes the API's URL validator (the initial host is public), and the browser follows the redirect to 169.254.169.254. The request timed out after 30s with nothing returned, apparently because the address isn't reachable from the pod. The guard did not stop it.
  • A direct private URL, or a hostname that resolves privately (10.0.0.1.nip.io), is refused, but by the API's validator before the browser is involved.

Expected: every hop is checked with isPublicHost, and a redirect to a non-public host aborts the navigation (blockedbyclient).

Possible fix: in the route handler, fetch with redirects disabled (route.fetch({ maxRedirects: 0 })). On a 3xx, resolve Location against the request URL, check it with isPublicHost, and either abort or route.fulfill the redirect response so the browser re-requests the next hop, which passes through the handler again. Add a test with a public redirect to a private address.

Context: appwrite-labs/cloud#6236 (cloud runs 0.3.5 since 2026-10-05).

主要言語
TypeScript
スター
8
フォーク
2
平均マージ
21分
マージ済み PR(30日)
2

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

appwrite/docker-browser のほかの issue

appwrite/docker-browser の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。