From: eiknat <68170752+eiknat@users.noreply.github.com> Date: Fri, 17 Jul 2020 22:46:59 +0000 (-0400) Subject: validate post URLs on the backend (#990) X-Git-Url: http://these/git/%7B%60%24%7BwebArchiveUrl%7D/%22%7B%7D/%24%7B%60data:application/%22https:/hacktivis.me/%7Bthis.state.user.avatar%7D?a=commitdiff_plain;h=03758a4f9232da8ceee849df57e17c4a8664cdfd;p=lemmy.git validate post URLs on the backend (#990) * added serverside url validation * api.post: use if let instead of is_some also add "invalid_url" to en.json Co-authored-by: John Doe --- diff --git a/server/src/api/post.rs b/server/src/api/post.rs index b9518f0e..61f3513b 100644 --- a/server/src/api/post.rs +++ b/server/src/api/post.rs @@ -37,6 +37,7 @@ use lemmy_utils::{ }; use serde::{Deserialize, Serialize}; use std::str::FromStr; +use url::Url; #[derive(Serialize, Deserialize, Debug)] pub struct CreatePost { @@ -162,6 +163,13 @@ impl Perform for Oper { return Err(APIError::err("site_ban").into()); } + if let Some(url) = data.url.as_ref() { + match Url::parse(url) { + Ok(_t) => (), + Err(_e) => return Err(APIError::err("invalid_url").into()), + } + } + // Fetch Iframely and pictrs cached image let (iframely_title, iframely_description, iframely_html, pictrs_thumbnail) = fetch_iframely_and_pictrs_data(&self.client, data.url.to_owned()).await; diff --git a/ui/translations/en.json b/ui/translations/en.json index 6e111c63..e9d768f2 100644 --- a/ui/translations/en.json +++ b/ui/translations/en.json @@ -277,5 +277,6 @@ "what_is": "What is", "cake_day_title": "Cake day:", "cake_day_info": "It's {{ creator_name }}'s cake day today!", - "invalid_post_title": "Invalid post title" + "invalid_post_title": "Invalid post title", + "invalid_url": "Invalid URL." }