Skip to content

Harden update links for v2.1.4 - #7

Closed
LabSchool-GR wants to merge 1 commit into
mainfrom
codex/v2.1.4-update-link-security
Closed

LabSchool-GR wants to merge 1 commit into
mainfrom
codex/v2.1.4-update-link-security

Conversation

@LabSchool-GR

Copy link
Copy Markdown
Owner

Summary

  • Restrict newly submitted update links to HTTP and HTTPS, with sensible length limits.
  • Prevent legacy update records with unsafe URI schemes from rendering clickable links.
  • Add noreferrer protection to external links opened in a new tab.
  • Add regression coverage for validation and legacy unsafe links.

The root cause was that update links accepted broader URL schemes and stored values were rendered directly. This change rejects unsafe schemes at input time and safely handles existing records without requiring a migration.

The unrelated local composer.lock dependency update is deliberately excluded from this PR.

Testing

  • php artisan test — 163 passed, 786 assertions
  • npm run build — not required; no compiled frontend assets changed
  • Manual smoke check completed where needed

Additional validation: composer validate --strict --no-check-publish passed and git diff --check reported no errors.

Changelog Draft

Security

  • Restrict update announcement links to browser-safe HTTP/HTTPS URLs and suppress unsafe legacy links.

Upgrade Notes

  • None.

Release Notes Check

  • This PR needs a changelog entry
  • This PR does not need a changelog entry
  • This PR introduces deploy or upgrade steps that must appear under Upgrade Notes

@LabSchool-GR
LabSchool-GR deleted the codex/v2.1.4-update-link-security branch July 6, 2026 12:49
@LabSchool-GR LabSchool-GR changed the title [codex] Harden update links for v2.1.4 Harden update links for v2.1.4 Jul 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant