Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 7 additions & 6 deletions index.js
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
'use strict'

const punycodeRegex = require('punycode-regex')()
const urlRegex = require('url-regex-safe')

const REGEX_HTTP_PROTOCOL = /^https?:\/\//i
Expand All @@ -9,12 +8,14 @@ module.exports = url => {
try {
const { href, hostname, origin, username, password } = new URL(url)
if (!REGEX_HTTP_PROTOCOL.test(href) || username || password) return false
const isIPv6 = hostname.startsWith('[') && hostname.endsWith(']')
const isPunycode = punycodeRegex.test(hostname)
// url-regex-safe cannot exact-match IPv6 or punycode authorities.
const exact = !isIPv6 && !isPunycode
// url-regex-safe cannot exact-match IPv6 authorities.
const exact = !(hostname.startsWith('[') && hostname.endsWith(']'))

// url-regex-safe's TLD list has no xn-- entries, so an IDN TLD has to be
// supplied; an ASCII one stays subject to the built-in public-suffix list.
const tld = hostname.slice(hostname.lastIndexOf('.') + 1)
const tlds = tld.startsWith('xn--') ? [tld] : undefined

const tlds = isPunycode ? [] : undefined
const regex = urlRegex({ apostrophes: true, exact, parens: true, tlds })
if (!regex.test(href)) return false

Expand Down
1 change: 0 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@
"whatwg"
],
"dependencies": {
"punycode-regex": "~1.0.1",
"re2": "~1.26.0",
"url-regex-safe": "~4.0.0"
},
Expand Down
7 changes: 6 additions & 1 deletion test/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,12 @@ const test = require('ava').default
'http://-kikobeats.com',
'http://internal/https://example.com/#:~:text=x',
'http://metadata/https://example.com/#:~:text=x',
'http://xn--internal/https://example.com/'
'http://xn--internal/https://example.com/',
'https://example.local/',
'https://xn--e1afmkfd.local/',
'https://пример.local/',
'https://xn--80a0aaa.internal/',
'https://xn--80a0aaa.invalidtld/'
])
).forEach(input => {
const url = httpUrl(input)
Expand Down