fix(docs): validate reference and redirect scope - #15
Merged
Merged
Conversation
matcra587
added this pull request to stack #18
September 21, 2026 23:55
matcra587
marked this pull request as ready for review
September 22, 2026 00:00
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
A foreign URL with a known documentation path could be silently interpreted as a local page, and redirects could leave the configured documentation scope. Validate origin, base path, encoding and version scope before lookup or fetch, while preserving supported slugs and Markdown URLs.
Test Procedure
mise run ci: formatting, lint, offline race tests, vulnerability checks, release checks and all five compilation targets.TestReferenceScope,TestLookupRejectsForeignAuthorityandTestLookupRedirectScopecover deceptive authorities, malformed encoding and redirects; rejected destinations receive zero requests.FuzzReferencerun.Pre-flight Checklist
Additional Notes
Full URLs must match the configured origin and base path. Query strings, protocol-relative URLs and enterprise/version paths now return explicit errors instead of being reinterpreted as current GitHub.com documentation.