Enforce HTTPS for Discord webhooks
This change updates the `validate_webhook_url` function to strictly enforce the use of `https://` for Discord webhook URLs. This prevents the accidental transmission of sensitive webhook tokens over unencrypted HTTP connections. Security Impact: - Prevents potential Man-in-the-Middle (MitM) attacks from capturing webhook tokens if a user inadvertently copies an `http://` URL (e.g. from a proxy or non-standard source). - Aligns with Discord's API security best practices. Changes: - Updated `WEBHOOK_URL_PATTERNS` regex to require `https`. - Updated `validate_webhook_url` logic to check for `https://` prefix. - Added unit test `test_http_url_rejected` to verify the fix.
This commit is contained in:
@@ -20,8 +20,8 @@ logger = logging.getLogger("comfyui_discordsend")
|
||||
|
||||
# Discord webhook URL patterns
|
||||
WEBHOOK_URL_PATTERNS = [
|
||||
r"https?://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https?://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
|
||||
]
|
||||
|
||||
|
||||
@@ -38,8 +38,8 @@ def validate_webhook_url(url: str) -> Tuple[bool, str]:
|
||||
if not url:
|
||||
return False, "Webhook URL is empty"
|
||||
|
||||
if not url.startswith("http"):
|
||||
return False, "Webhook URL must start with http:// or https://"
|
||||
if not url.startswith("https://"):
|
||||
return False, "Webhook URL must start with https://"
|
||||
|
||||
# Check against known patterns
|
||||
for pattern in WEBHOOK_URL_PATTERNS:
|
||||
|
||||
@@ -131,6 +131,12 @@ class TestWebhookValidation(unittest.TestCase):
|
||||
is_valid, message = validate_webhook_url("http://localhost:8080/admin")
|
||||
self.assertFalse(is_valid)
|
||||
|
||||
def test_http_url_rejected(self):
|
||||
"""Should reject HTTP URLs (must be HTTPS)."""
|
||||
is_valid, message = validate_webhook_url("http://discord.com/api/webhooks/123/abc")
|
||||
self.assertFalse(is_valid)
|
||||
self.assertIn("must start with https://", message)
|
||||
|
||||
def test_ip_encoding_urls(self):
|
||||
"""Should reject alternate IP encodings."""
|
||||
self.assertFalse(validate_webhook_url("http://127.0.0.1")[0])
|
||||
|
||||
Reference in New Issue
Block a user