Merge pull request #19 from AEmotionStudio/sentinel-enforce-https-webhooks-16770274636701043555
🛡️ Sentinel: Enforce HTTPS for Discord Webhooks
This commit is contained in:
@@ -20,8 +20,8 @@ logger = logging.getLogger("comfyui_discordsend")
|
||||
|
||||
# Discord webhook URL patterns
|
||||
WEBHOOK_URL_PATTERNS = [
|
||||
r"https?://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https?://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https://(?:www\.)?discord(?:app)?\.com/api/webhooks/\d+/[\w-]+$",
|
||||
r"https://(?:www\.)?discordapp\.com/api/webhooks/\d+/[\w-]+$",
|
||||
]
|
||||
|
||||
|
||||
@@ -38,8 +38,8 @@ def validate_webhook_url(url: str) -> Tuple[bool, str]:
|
||||
if not url:
|
||||
return False, "Webhook URL is empty"
|
||||
|
||||
if not url.startswith("http"):
|
||||
return False, "Webhook URL must start with http:// or https://"
|
||||
if not url.startswith("https://"):
|
||||
return False, "Webhook URL must start with https://"
|
||||
|
||||
# Check against known patterns
|
||||
for pattern in WEBHOOK_URL_PATTERNS:
|
||||
|
||||
@@ -131,6 +131,12 @@ class TestWebhookValidation(unittest.TestCase):
|
||||
is_valid, message = validate_webhook_url("http://localhost:8080/admin")
|
||||
self.assertFalse(is_valid)
|
||||
|
||||
def test_http_url_rejected(self):
|
||||
"""Should reject HTTP URLs (must be HTTPS)."""
|
||||
is_valid, message = validate_webhook_url("http://discord.com/api/webhooks/123/abc")
|
||||
self.assertFalse(is_valid)
|
||||
self.assertIn("must start with https://", message)
|
||||
|
||||
def test_ip_encoding_urls(self):
|
||||
"""Should reject alternate IP encodings."""
|
||||
self.assertFalse(validate_webhook_url("http://127.0.0.1")[0])
|
||||
|
||||
Reference in New Issue
Block a user