Keep a link preview's link and image off this Campfire's own host

A preview belongs to the page it previews, so both URLs point somewhere
else. An absolute URL on our own host passed the scheme and host checks,
and every reader's browser fetched it with their session attached, which
turns a message into a GET request made on the reader's behalf.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186eyzivcTn6wqjEE4Wnxdt
This commit is contained in:
Rosa Gutierrez
2026-09-11 19:08:54 +02:00
parent c3ae67a2b6
commit eceec2898b
3 changed files with 44 additions and 7 deletions
+16
View File
@@ -35,6 +35,22 @@ class RoomsControllerTest < ActionDispatch::IntegrationTest
assert_match "Free cookies", response.body
end
test "show renders a link preview written by hand without its image pointed at this Campfire" do
room = rooms(:watercooler)
own_url = room_url(room, host: "www.example.com")
post room_messages_url(room, format: :turbo_stream), params: { message: {
body: link_preview_body(href: own_url, url: own_url),
client_message_id: "same-host-preview" } }
assert_response :success
get room_url(room)
assert_response :success
assert_no_match %r{<img src="#{Regexp.escape(own_url)}"}, response.body
assert_no_match %r{<a rel="noreferrer" target="_blank" href="#{Regexp.escape(own_url)}"}, response.body
assert_match "Free cookies", response.body
end
test "show renders an unfurled link preview" do
room = rooms(:watercooler)
post room_messages_url(room, format: :turbo_stream), params: { message: {
@@ -19,6 +19,22 @@ class ActionText::Attachment::OpengraphEmbedTest < ActiveSupport::TestCase
end
end
test "drops a link and an image on this Campfire's own host" do
Current.set request: ActionDispatch::TestRequest.create("HTTP_HOST" => "once.campfire.test") do
[ "https://once.campfire.test/rooms/1", "http://once.campfire.test/rooms/1",
"https://ONCE.Campfire.Test/rooms/1" ].each do |value|
embed = embed_from href: value, url: value
assert_nil embed.href, "expected #{value.inspect} to be dropped as a link"
assert_nil embed.url, "expected #{value.inspect} to be dropped as an image"
end
embed = embed_from href: "https://example.com/page", url: "https://example.com/image.png"
assert_equal "https://example.com/page", embed.href
assert_equal "https://example.com/image.png", embed.url
end
end
test "renders the image and the link when both are web URLs" do
html = render_embed href: "https://example.com/page", url: "https://example.com/image.png"