fix:image url validation and signout post (#24420)
* refac(routers): reject external URLs in profile/model image handlers * refac(ui): centralize image URL validation in safeImageUrl helper * refac(auths): make signout POST-only * refac: gate external profile image redirect behind ENABLE_PROFILE_IMAGE_URL_FORWARDING Restore the 302 redirect for external http(s) profile image URLs in the user and model profile-image endpoints, but gate it behind a new ENABLE_PROFILE_IMAGE_URL_FORWARDING env flag (default: True). Existing deployments that rely on external profile image forwarding continue to work unchanged. Operators who want to suppress the redirect (to prevent client-side IP/UA/Referer leaks) can set the flag to False.
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
import { mergeAttributes, Node, nodeInputRule } from '@tiptap/core';
|
||||
import { safeImageUrl } from '$lib/utils/safeImageUrl';
|
||||
|
||||
export interface ImageOptions {
|
||||
/**
|
||||
@@ -137,12 +138,12 @@ export const Image = Node.create<ImageOptions>({
|
||||
if (editorFiles && node.attrs.src.startsWith('data://')) {
|
||||
const file = editorFiles.find((f) => f.id === fileId);
|
||||
if (file) {
|
||||
img.setAttribute('src', file.url || '');
|
||||
img.setAttribute('src', safeImageUrl(file.url || ''));
|
||||
} else {
|
||||
img.setAttribute('src', '/image-placeholder.png');
|
||||
}
|
||||
} else {
|
||||
img.setAttribute('src', node.attrs.src || '');
|
||||
img.setAttribute('src', safeImageUrl(node.attrs.src || ''));
|
||||
}
|
||||
|
||||
img.setAttribute('alt', node.attrs.alt || '');
|
||||
@@ -153,7 +154,7 @@ export const Image = Node.create<ImageOptions>({
|
||||
if (files && node.attrs.src.startsWith('data://')) {
|
||||
const file = editorFiles.find((f) => f.id === fileId);
|
||||
if (file) {
|
||||
img.setAttribute('src', file.url || '');
|
||||
img.setAttribute('src', safeImageUrl(file.url || ''));
|
||||
} else {
|
||||
img.setAttribute('src', '/image-placeholder.png');
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user