Skip to content

0.3.2: follow an avatar URL's redirects only within its origin - #2

Merged
snakajima merged 1 commit into
mainfrom
fix/url-redirects
Oct 6, 2026
Merged

snakajima merged 1 commit into
mainfrom
fix/url-redirects

Conversation

@snakajima

Copy link
Copy Markdown
Contributor

Summary

  • loadAvatar(url) used to follow any redirect. The package-folder check limits the paths a package declares, but not where a redirect goes, so a public host could redirect requests to an internal service.
  • Redirects are now followed manually (at most 5) and only within the same origin. A redirect to another host fails with an error that names the final URL. GitHub's github.com/.../raw/... links redirect to raw.githubusercontent.com, so use the latter; the README says so.
  • Version 0.3.2.

Found in CodeRabbit's review of receptron/mulmocast-cli#1598, which applies the same rule to its cache-stamp requests.

Test plan

  • New test: a same-origin redirect is followed, and a redirect to another host is refused
  • npm run lint, npm run typecheck, npm test (59 tests), package smoke
  • The real ani URL on raw.githubusercontent.com loads (22 assets). The github.com/.../raw/... form gets the "use the final URL" error.

🤖 Generated with Claude Code

work in mesh-avatar-studio

The package-folder check covers the paths a package declares, not where a redirect goes, so a
public host could redirect requests to an internal one. Redirects are now followed manually, at
most 5, and only within the same origin. github.com/.../raw/... links, which redirect to
raw.githubusercontent.com, get an error naming the final URL. Found in review of
receptron/mulmocast-cli#1598.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@snakajima
snakajima merged commit e0b8335 into main Oct 6, 2026
7 checks passed
@snakajima
snakajima deleted the fix/url-redirects branch October 6, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant