Commit e349e67
[Confluence] Fix CodeQL incomplete URL substring sanitization
Use urlparse to extract and check the hostname directly instead of
naive substring matching, preventing spoofing via paths like
evil.com/atlassian.net/...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 09af08a commit e349e67
1 file changed
Lines changed: 8 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
8 | 10 | | |
9 | 11 | | |
10 | 12 | | |
| |||
21 | 23 | | |
22 | 24 | | |
23 | 25 | | |
24 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
25 | 32 | | |
26 | 33 | | |
27 | 34 | | |
| |||
0 commit comments