fix: handle relative URLs in Websocket domain filter script (#624)
* fix: handle relative URLs in domain filter WebSocket script Pass location.href as base URL to the URL constructor so relative URLs (e.g. "/path" or "//host/path") resolve correctly instead of throwing. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Affirm-Skill: commit-and-push * fix: apply domain filter review followups Use location.href as base in native WebSocket handler to match EventSource/sendBeacon, remove redundant comment, add test coverage. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: ctate <366502+ctate@users.noreply.github.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
ctate
parent
fdc09c95f4
commit
755fa50400
@@ -184,7 +184,7 @@ pub async fn install_domain_filter_script(
|
||||
const OrigWS = window.WebSocket;
|
||||
window.WebSocket = function(url, protocols) {{
|
||||
try {{
|
||||
const u = new URL(url);
|
||||
const u = new URL(url, location.href);
|
||||
if (!_isDomainAllowed(u.hostname)) throw new DOMException('WebSocket blocked: ' + u.hostname, 'SecurityError');
|
||||
}} catch(e) {{ if (e instanceof DOMException) throw e; }}
|
||||
return new OrigWS(url, protocols);
|
||||
|
||||
Reference in New Issue
Block a user