Skip to content

Security: Add URL validation and logging for unsanitized URLs #81

Description

@coderabbitai

Background

When URL sanitization is disabled (introduced in #80), we should still implement basic security measures:

  1. Add basic URL validation for unsanitized redirect URLs
  2. Add logging when URL sanitization is bypassed

References

Requirements

  • Implement basic URL validation using URL constructor
  • Add warning logs when sanitization is bypassed
  • Handle invalid URLs appropriately with clear error messages

/cc @DanielRivers

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions