Skip to content

Replica: prevent nil description errors in routes view#69

Open
lucaforni wants to merge 9 commits into
main-modalsourcefrom
sandroshu-postal-patch-1
Open

Replica: prevent nil description errors in routes view#69
lucaforni wants to merge 9 commits into
main-modalsourcefrom
sandroshu-postal-patch-1

Conversation

@lucaforni
Copy link
Copy Markdown

Questa PR replica la PR originale: postalserver#3568

Autore originale: @sandroshu
Branch originale: patch-1
Repository originale: sandroshu/postal


Handling missing route endpoint
descriptions in routes/index.html.haml to avoid 500 errors when associated objects are nil or partially removed.

Fixes issue: postalserver#3567

adamcooke and others added 9 commits February 1, 2026 14:48
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
The app-wide CSP already blocks inline script execution, but the HTML
preview iframe for a stored email was same-origin and un-sandboxed, and
the html_raw response had no per-action hardening. Add a sandbox on the
iframe and tighten the CSP on html_raw to script-src 'none' with
nosniff and no-referrer so the preview has defence in depth against a
future CSP bypass or regression.

Relates to GHSA-f6g9-8555-cw28.
The /img/<server>/<message> endpoint accepted a src=<url> query
parameter and proxied the body of that URL back to the caller. Nothing
in the codebase ever produces a src= parameter — the parser only
inserts a plain tracking pixel and rewrites href links — so this branch
is dead code inherited from the original AppMail import.

Drop the src branch: requests with src now return 400. The no-src path
that serves the tracking pixel and records loads is unchanged, and a
spec covers both the pixel-serving path and the removed branch.
The endpoint and domain option helpers interpolated model attributes
straight into an HTML string before marking the whole buffer html_safe.
Wrap the interpolations in h() so untrusted attributes can't break out
of the surrounding tag.

Also stop the helpers glob in rails_helper from eagerly requiring
_spec.rb files so helper specs can live under spec/helpers/, and add a
small application helper spec covering the escape behaviour.
url_with_return_to only checked that return_to started with a forward
slash, which also allowed protocol-relative values like //host and
/\host. Rails 7.1 already refuses to follow those via redirect_to, so
the user just saw a 500. Reject the same shapes in the helper instead
so we fall back to the default URL cleanly.

Adds a sessions request spec covering the rejected shapes plus the
happy-path relative redirect.
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Handling missing route endpoint
descriptions in routes/index.html.haml to avoid 500 errors when
associated objects are nil or partially removed.

Signed-off-by: Sándor <9724897+sandroshu@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants