test(security): parse Kimi Web URL host instead of substring match (CodeQL #689) (#5928)

Alert js/incomplete-url-substring-sanitization: the Kimi Web executor
test asserted result.url.includes("www.kimi.com"), which a hostile host
like www.kimi.com.evil.net would also satisfy. Parse the URL and assert
on the exact hostname (new URL(result.url).hostname === "www.kimi.com"),
which is both a stronger check and clears the CodeQL warning.
This commit is contained in:
Diego Rodrigues de Sa e Souza
2026-07-02 13:49:21 -03:00
committed by GitHub
parent be420afe1f
commit dfbc89f97b

View File

@@ -679,8 +679,13 @@ test("Kimi Web: targets www.kimi.com (international)", async () => {
credentials: { apiKey: "kimi-auth=eyJ.eyJzdWI.signature" },
});
assert.ok(result.response instanceof Response);
assert.ok(result.url.includes("www.kimi.com"), `got ${result.url}`);
assert.ok(!result.url.includes("moonshot.cn"));
// Parse the URL and assert on the exact hostname rather than a substring
// match — `includes("www.kimi.com")` would also accept a hostile host like
// `www.kimi.com.evil.net` or `evil.net/?x=www.kimi.com` (CodeQL
// js/incomplete-url-substring-sanitization).
const host = new URL(result.url).hostname;
assert.equal(host, "www.kimi.com", `got ${result.url}`);
assert.notEqual(host, "www.moonshot.cn", `got ${result.url}`);
} finally {
restore.restore();
}