summaryrefslogtreecommitdiff
path: root/packages/backend/src
diff options
context:
space:
mode:
authorJulia Johannesen <julia@insertdomain.name>2025-04-27 13:05:09 -0400
committerJulia Johannesen <julia@insertdomain.name>2025-04-27 13:05:09 -0400
commit0bb4e57b0c646a20aa46e6cac545b37682629e89 (patch)
treecae0d041c41353c1c8a9e8616abc3f609de87194 /packages/backend/src
parentmerge: 2025.2.2 (!927) (diff)
downloadsharkey-0bb4e57b0c646a20aa46e6cac545b37682629e89.tar.gz
sharkey-0bb4e57b0c646a20aa46e6cac545b37682629e89.tar.bz2
sharkey-0bb4e57b0c646a20aa46e6cac545b37682629e89.zip
Security fixes
Co-Authored-By: dakkar <dakkar@thenautilus.net>
Diffstat (limited to 'packages/backend/src')
-rw-r--r--packages/backend/src/core/activitypub/ApRendererService.ts4
-rw-r--r--packages/backend/src/server/web/UrlPreviewService.ts10
2 files changed, 5 insertions, 9 deletions
diff --git a/packages/backend/src/core/activitypub/ApRendererService.ts b/packages/backend/src/core/activitypub/ApRendererService.ts
index cb9b74f6d7..44eb029a35 100644
--- a/packages/backend/src/core/activitypub/ApRendererService.ts
+++ b/packages/backend/src/core/activitypub/ApRendererService.ts
@@ -496,9 +496,7 @@ export class ApRendererService {
const attachment = profile.fields.map(field => ({
type: 'PropertyValue',
name: field.name,
- value: (field.value.startsWith('http://') || field.value.startsWith('https://'))
- ? `<a href="${new URL(field.value).href}" rel="me nofollow noopener" target="_blank">${new URL(field.value).href}</a>`
- : field.value,
+ value: this.mfmService.toHtml(mfm.parse(field.value)),
}));
const emojis = await this.getEmojis(user.emojis);
diff --git a/packages/backend/src/server/web/UrlPreviewService.ts b/packages/backend/src/server/web/UrlPreviewService.ts
index 19dac1dfb8..f2a93e0958 100644
--- a/packages/backend/src/server/web/UrlPreviewService.ts
+++ b/packages/backend/src/server/web/UrlPreviewService.ts
@@ -52,12 +52,10 @@ export class UrlPreviewService {
@bindThis
private wrap(url?: string | null): string | null {
return url != null
- ? url.match(/^https?:\/\//)
- ? `${this.config.mediaProxy}/preview.webp?${query({
- url,
- preview: '1',
- })}`
- : url
+ ? `${this.config.mediaProxy}/preview.webp?${query({
+ url,
+ preview: '1',
+ })}`
: null;
}