MCPcopy Create free account
hub / github.com/boringstack-xyz/boringstack / sanitizeTargetPath

Function sanitizeTargetPath

apps/ui/public/sw.js:32–48  ·  view source on GitHub ↗

* Reduce an inbound payload URL to a safe same-origin app path. * Returns "/" when the input is missing, malformed, or off-origin.

(rawUrl)

Source from the content-addressed store, hash-verified

30 * Returns "/" when the input is missing, malformed, or off-origin.
31 */
32function sanitizeTargetPath(rawUrl) {
33 if (typeof rawUrl !== "string" || rawUrl === "") {
34 return "/";
35 }
36
37 try {
38 const parsed = new URL(rawUrl, self.location.origin);
39
40 if (parsed.origin !== self.location.origin) {
41 return "/";
42 }
43
44 return `${parsed.pathname}${parsed.search}${parsed.hash}`;
45 } catch {
46 return "/";
47 }
48}
49
50/** Exact same-origin path/search/hash compare. No substring matching. */
51function clientPathMatches(clientUrl, targetPath) {

Callers 1

sw.jsFile · 0.70

Calls

no outgoing calls

Tested by

no test coverage detected