Skip to content
File

Blob: src/client/lib/email-html/url-policy.ts

typescript46 lines
1export function stripQuotes(value: string) {
2 return value.trim().replace(/^['"]|['"]$/g, "");
3}
4 
5export function isUnsafeUrl(value: string) {
6 const normalized = stripQuotes(value).trim().toLowerCase();
7 return (
8 normalized.startsWith("javascript:") ||
9 normalized.startsWith("vbscript:") ||
10 normalized.startsWith("file:") ||
11 normalized.startsWith("data:text/html") ||
12 normalized.startsWith("data:application/xhtml+xml")
13 );
14}
15 
16export function isAllowedInlineResourceUrl(value: string) {
17 const normalized = stripQuotes(value).trim().toLowerCase();
18 return (
19 normalized.startsWith("data:") ||
20 normalized.startsWith("cid:") ||
21 normalized.startsWith("about:") ||
22 normalized.startsWith("blob:")
23 );
24}
25 
26export function isRemoteResourceUrl(value: string) {
27 const normalized = stripQuotes(value).trim().toLowerCase();
28 return normalized.startsWith("https://") || normalized.startsWith("http://") || normalized.startsWith("//");
29}
30 
31export function isAllowedNavigationUrl(value: string) {
32 const normalized = stripQuotes(value).trim().toLowerCase();
33 
34 if (!normalized || normalized.startsWith("#")) {
35 return true;
36 }
37 
38 return (
39 normalized.startsWith("https://") ||
40 normalized.startsWith("http://") ||
41 normalized.startsWith("//") ||
42 normalized.startsWith("mailto:") ||
43 normalized.startsWith("tel:")
44 );
45}