Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(sdk): ignore messages from a different origin and sanitize URLs #8879

Open
wants to merge 8 commits into
base: develop
Choose a base branch
from

Conversation

scmmishra
Copy link
Member

@scmmishra scmmishra commented Feb 7, 2024

This PR includes some specific security related fixes

  1. Validate the origin of any message events
  2. Sanitize URLs before opening them

Copy link

linear bot commented Feb 7, 2024

@scmmishra scmmishra changed the title fix: ignore messages from a different origin fix(sdk): ignore messages from a different origin and sanitize URLs Feb 12, 2024
@scmmishra scmmishra marked this pull request as ready for review February 12, 2024 14:28
@scmmishra
Copy link
Member Author

@pranavrajs PTAL

@scmmishra
Copy link
Member Author

@pranavrajs PTAL whenever you can

1 similar comment
@scmmishra
Copy link
Member Author

@pranavrajs PTAL whenever you can

Copy link

🐢 Turtley slow progress alert! This pull request has been idle for over 30 days. Can we please speed things up and either merge it or release it back into the wild?

@github-actions github-actions bot added the stale label Apr 21, 2024
@scmmishra
Copy link
Member Author

@pranavrajs PTAL whenever you can

@github-actions github-actions bot removed the stale label Apr 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant