url reader: follow html meta-refresh redirects (getnews shortlinks) with ssrf re-guard
This commit is contained in:
@@ -31,7 +31,10 @@ refused without DNS.
|
||||
|
||||
Redirects are followed manually; each hop's target passes URL-02 and
|
||||
URL-03 again. A public URL that 302-redirects to `localhost` or an
|
||||
internal IP is refused at the redirect, not fetched.
|
||||
internal IP is refused at the redirect, not fetched. **HTML
|
||||
meta-refresh** redirects (link shorteners, the old getnews stubs) are
|
||||
also followed — the target is SSRF-re-guarded and fetched, so the
|
||||
reader returns the real article, not the "Redirecting…" stub.
|
||||
|
||||
### URL-05 — Fetched text is bounded and sanitized (coverage: test)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user