Repository navigation
out_opensearch: limit what a host placeholder can expand to - #192
Merged
Merged
Conversation
kenhys
marked this pull request as ready for review
September 17, 2026 01:35
Watson1978
requested changes
Sep 17, 2026
Watson1978
reviewed
Sep 18, 2026
Watson1978
requested changes
Oct 7, 2026
Before: a placeholder in `host`/`hosts` was expanded as is, so a tag or a record field could add a host with ",", userinfo with "@" or a path with "/", move the request to another domain, or drop the host with an empty value. The configured user, password and custom_headers were then sent to that host. After: each value is checked before the setting is expanded, so it can only fill in the part of a host name that the placeholder stands for: one label, a sub domain of a domain that the operator fixed with two or more names, or a whole host name with a port. An IPv6 address is allowed where the operator wrote the "[]" or the scheme that `URI()` needs. A placeholder used with credentials also logs a warning at startup, and the README asks for a fixed domain that the operator controls, because two fixed names alone do not make a destination trusted. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Before: A placeholder in
host/hostswas expanded and passed to the connection options as is. So a tag or a record field could add a host with ",", userinfo with "@" or a path with "/". The configured user, password and custom_headers were then sent to that host.After: Each placeholder value is checked before the whole setting is expanded, so a value can only fill in a host name and a port. The rest of the setting, such as the "," between hosts or a scheme, userinfo and path the operator wrote, is left as it is. A placeholder used together with credentials logs a warning at startup.