Enforce HTTPS for Discord webhooks

This change updates the `validate_webhook_url` function to strictly enforce the use of `https://` for Discord webhook URLs. This prevents the accidental transmission of sensitive webhook tokens over unencrypted HTTP connections.

Security Impact:
- Prevents potential Man-in-the-Middle (MitM) attacks from capturing webhook tokens if a user inadvertently copies an `http://` URL (e.g. from a proxy or non-standard source).
- Aligns with Discord's API security best practices.

Changes:
- Updated `WEBHOOK_URL_PATTERNS` regex to require `https`.
- Updated `validate_webhook_url` logic to check for `https://` prefix.
- Added unit test `test_http_url_rejected` to verify the fix.
This commit is contained in:
google-labs-jules[bot]
2026-01-17 01:14:33 +00:00
parent 2a37c1b410
commit cd2052757a
2 changed files with 10 additions and 4 deletions
+4 -4
View File
@@ -20,8 +20,8 @@ logger = logging.getLogger("comfyui_discordsend")
# Discord webhook URL patterns
WEBHOOK_URL_PATTERNS = [
r"https?://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
r"https?://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
r"https://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
r"https://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
]
@@ -38,8 +38,8 @@ def validate_webhook_url(url: str) -> Tuple[bool, str]:
if not url:
return False, "Webhook URL is empty"
if not url.startswith("http"):
return False, "Webhook URL must start with http:// or https://"
if not url.startswith("https://"):
return False, "Webhook URL must start with https://"
# Check against known patterns
for pattern in WEBHOOK_URL_PATTERNS:
+6
View File
@@ -131,6 +131,12 @@ class TestWebhookValidation(unittest.TestCase):
is_valid, message = validate_webhook_url("http://localhost:8080/admin")
self.assertFalse(is_valid)
def test_http_url_rejected(self):
"""Should reject HTTP URLs (must be HTTPS)."""
is_valid, message = validate_webhook_url("http://discord.com/api/webhooks/123/abc")
self.assertFalse(is_valid)
self.assertIn("must start with https://", message)
def test_ip_encoding_urls(self):
"""Should reject alternate IP encodings."""
self.assertFalse(validate_webhook_url("http://127.0.0.1")[0])