mirror of
https://github.com/tenrok/axios.git
synced 2026-06-14 18:42:33 +03:00
fix(sec): disregard protocol-relative URL to remediate SSRF (#6539)
* fix(sec): disregard protocol-relative URL to remediate SSRF Signed-off-by: hainenber <dotronghai96@gmail.com> * feat(test/unit/regression): add regression test to ensure SNYK-JS-AXIOS-7361793 fixed in future version Signed-off-by: hainenber <dotronghai96@gmail.com> * chore: add EoF newline + comments Signed-off-by: hainenber <dotronghai96@gmail.com> * chore: fix eslint issues Signed-off-by: hainenber <dotronghai96@gmail.com> * Update SNYK-JS-AXIOS-7361793.js Co-authored-by: tom-reinders <tom-reinders@users.noreply.github.com> --------- Signed-off-by: hainenber <dotronghai96@gmail.com> Co-authored-by: tom-reinders <tom-reinders@users.noreply.github.com>
This commit is contained in:
@@ -12,8 +12,8 @@ describe('helpers::isAbsoluteURL', function () {
|
||||
expect(isAbsoluteURL('!valid://example.com/')).toBe(false);
|
||||
});
|
||||
|
||||
it('should return true if URL is protocol-relative', function () {
|
||||
expect(isAbsoluteURL('//example.com/')).toBe(true);
|
||||
it('should return false if URL is protocol-relative', function () {
|
||||
expect(isAbsoluteURL('//example.com/')).toBe(false);
|
||||
});
|
||||
|
||||
it('should return false if URL is relative', function () {
|
||||
|
||||
Reference in New Issue
Block a user