From ea2c64c9a6fbc22bffbac4e2e57ce0762f5e03ad Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Tue, 15 Sep 2026 18:13:53 +0200 Subject: feat(notifications): strip remote inline image sources A notification is untrusted input. Inline now renders only for local sources; an http(s) source is removed before the RichText body is shown, so a remote sender cannot make the shell fetch a URL. The row and the balloon share the one sanitizer in the Notify singleton. --- shared/Notify.qml | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'shared') diff --git a/shared/Notify.qml b/shared/Notify.qml index 897e50b..c79f5f5 100644 --- a/shared/Notify.qml +++ b/shared/Notify.qml @@ -65,6 +65,14 @@ Singleton { } function close(id) { root.run(["close", String(id)]); } function closeAll() { root.run(["close-all"]); } + + // Inline images are local only. A notification is untrusted input, and a + // remote would otherwise make the shell fetch a URL, which leaks + // that the notification was shown. This removes such tags before the + // RichText body renders; a local path or file:// source is left alone. + function sanitize(body) { + return (body || "").replace(/]*\bsrc\s*=\s*["']?\s*https?:\/\/[^>]*>/gi, ""); + } function action(id, key) { root.run(["action", String(id), key]); } function clearHistory() { root.run(["clear-history"]); } -- cgit v1.2.3