From dfbc89f97b6c27ea34fcdb220d0cac6aa630ecb6 Mon Sep 17 00:00:00 2001 From: Diego Rodrigues de Sa e Souza <8016841+diegosouzapw@users.noreply.github.com> Date: Thu, 2 Jul 2026 13:49:21 -0300 Subject: [PATCH] test(security): parse Kimi Web URL host instead of substring match (CodeQL #689) (#5928) Alert js/incomplete-url-substring-sanitization: the Kimi Web executor test asserted result.url.includes("www.kimi.com"), which a hostile host like www.kimi.com.evil.net would also satisfy. Parse the URL and assert on the exact hostname (new URL(result.url).hostname === "www.kimi.com"), which is both a stronger check and clears the CodeQL warning. --- tests/unit/web-cookie-providers-new.test.ts | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/tests/unit/web-cookie-providers-new.test.ts b/tests/unit/web-cookie-providers-new.test.ts index 1a9d340484..2cc59bcd23 100644 --- a/tests/unit/web-cookie-providers-new.test.ts +++ b/tests/unit/web-cookie-providers-new.test.ts @@ -679,8 +679,13 @@ test("Kimi Web: targets www.kimi.com (international)", async () => { credentials: { apiKey: "kimi-auth=eyJ.eyJzdWI.signature" }, }); assert.ok(result.response instanceof Response); - assert.ok(result.url.includes("www.kimi.com"), `got ${result.url}`); - assert.ok(!result.url.includes("moonshot.cn")); + // Parse the URL and assert on the exact hostname rather than a substring + // match — `includes("www.kimi.com")` would also accept a hostile host like + // `www.kimi.com.evil.net` or `evil.net/?x=www.kimi.com` (CodeQL + // js/incomplete-url-substring-sanitization). + const host = new URL(result.url).hostname; + assert.equal(host, "www.kimi.com", `got ${result.url}`); + assert.notEqual(host, "www.moonshot.cn", `got ${result.url}`); } finally { restore.restore(); }