Skip to content

fix: nightly hardening - remote URL credential guard - #19

Open
mouse-value-add wants to merge 1 commit into
mainfrom
chore/nightly-hardening-20260513-url-credentials-guard
Open

fix: nightly hardening - remote URL credential guard#19
mouse-value-add wants to merge 1 commit into
mainfrom
chore/nightly-hardening-20260513-url-credentials-guard

Conversation

@mouse-value-add

Copy link
Copy Markdown
Collaborator

Problem\nRemote profile loading accepted URLs with embedded credentials (for example ). Even with HTTPS, this pattern can leak secrets in logs/history and is not needed because token auth already exists in fetch options.\n\n## Approach\n- Added an early validation guard in to reject URLs that include or components.\n- Return a deterministic with message: .\n- Added a unit test to verify credentialed URLs are rejected before any network call is attempted.\n\n## Verification\n- Ran:

you-md@0.2.0 test
vitest run --run test/parser/loadFromUrl.test.ts

RUN v2.1.9 /Users/mouse/.openclaw/workspace/nightly/you.md

✓ test/parser/loadFromUrl.test.ts (5 tests) 8ms

Test Files 1 passed (1)
Tests 5 passed (5)
Start at 14:45:01
Duration 236ms (transform 34ms, setup 0ms, collect 39ms, tests 8ms, environment 0ms, prepare 27ms)\n- Result: all tests pass (including new credential-guard test).\n\n## Risks\n- Minor behavior change for callers currently relying on credentialed URLs. Those calls now fail fast with explicit guidance.\n\n## Rollback plan\n- Revert commit to restore previous behavior.\n

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant