Skip to content

Comments

Fix: Secure YouTube hostname validation#91

Open
RinZ27 wants to merge 1 commit intosteipete:mainfrom
RinZ27:fix/secure-youtube-validation
Open

Fix: Secure YouTube hostname validation#91
RinZ27 wants to merge 1 commit intosteipete:mainfrom
RinZ27:fix/secure-youtube-validation

Conversation

@RinZ27
Copy link

@RinZ27 RinZ27 commented Feb 15, 2026

The current YouTube hostname validation uses .includes() or loose .endsWith(), which can be bypassed by malicious domains like attacker-youtube.com.

I've switched to strict checks for youtube.com and its subdomains to prevent potential token leakage or incorrect scraper selection. I also added security test cases to content.url.test.ts to verify the fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant