Yeah this needs to be addressed ASAP.
Lemmy
Everything about Lemmy; bugs, gripes, praises, and advocacy.
For discussion about the lemmy.ml instance, go to [email protected].
While this is a critical issue, it makes me trust the platform even more, thanks to people like you who are committed to improving the security. So thanks for reporting this and hopefully it will be fixed as soon as possible ๐
Fixed 3 minutes ago.. cool!
Noice. Might need to let the Kbin dev know in case this affects them too
hopefully that works?
What about Gemini and gopher links?
jesus will protect me
May the Lord have mercy on us all.
Shit this is baaaaaad
Is this how u/spez will take us down?
Jk. Commenting to show activity on the post.
Well. Fuck.
excellent find. well done!
Patching: Allow only beginning with https:// (and maybe http://) might avoid related issues with any other protocols that the various browsers support?
Agreed, I recommended filtering to only http(s) links in the github issue, I just made this x-post. I don't see a strong reason to let people link to weird things like file:
and data:
, or deeplink to installed apps on your computer/phone. Filtering the scheme to just http(s) is how Nutomic seems to have fixed it in the backend from what I can tell (I am not a rust dev).