fix(relay): compare link-preview canonical to normalized content URLs - #8038
Draft
hunchulchoi wants to merge 2 commits into
Draft
hunchulchoi wants to merge 2 commits into
hunchulchoi wants to merge 2 commits into
Conversation
2ebfde9 bound VerifyAssertion::verify_assertion to a per-request CommunityBinding, but transport.rs still reached for http_denial through nip_fi_http's private import and its test double kept the two-parameter signature, so cargo build/cargo test on main fail with E0603/E0050. Point the call site at nip_fi_core where http_denial lives, and give the test stub the community parameter. Signed-off-by: choi <choi@dgst.me> Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Clients canonicalize preview URLs through the WHATWG parser before signing the snapshot tag, so the stored canonical legitimately differs from the literal message text: `https://host` serializes with a trailing `/`, non-ASCII segments percent-encode, and scheme/host fold to lowercase. The byte-for-byte `content.contains(canonical)` check then rejects the send outright — a plain `https://b2b-demo.devfor.link` message 400s with "invalid link-preview canonical URL" even though the link is right there. Compare normalized forms instead: extract URL-shaped tokens from the content (whitespace-delimited text, markdown `[label](target)` payloads, angle/quote-wrapped forms) and accept when any parses to the same URL. The anti-spoof property is unchanged — a snapshot still has to name a URL the message actually links to. Signed-off-by: choi <choi@dgst.me> Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🔐 Codex Security Review
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
https://b2b-demo.devfor.linkfails with400 invalid link-preview canonical URL, because the desktop client canonicalizes preview URLs through the WHATWG parser (new URL().href) — which serializeshttps://hostwith a trailing/— while ingest demandedevent.content.contains(canonical)byte-for-byte.…/한글vs…/%ED%95%9C%EA%B8%80), folded scheme/host case, and markdown[label](target)wrappers.validate_link_preview_tagsnow accepts the snapshot when any URL-shaped token in the content parses to the same normalizedurl::Url— keeping the anti-spoof property that the preview names a link actually present in the message. Tokens are whitespace-delimited; markdown targets and angle/quote-wrapped forms are unwrapped, with the untrimmed token kept as a candidate so URLs legitimately ending in)or.still match.Also includes a first commit repairing
main's build:2ebfde9leftapi/git/transport.rscallinghttp_denialthroughnip_fi_http's private import (E0603) and its test stub on the old two-parameterVerifyAssertionsignature (E0050), socargo build/cargo teston current main fail. Happy to split that out if preferred.Test plan
cargo test -p buzz-relay link_preview— 10 tests pass, including new coverage: bare root URL vs trailing-slash canonical, markdown/angle-wrapped/scheme-less forms, UTF-8 content vs percent-encoded canonical, and rejection cases (absent link, wrong host, bare-word non-match)Generated with Devin