1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
//! The `href` type.
//!
//! **This is its own module because of the tuple field.** A private field is
//! private to the MODULE, and `web.rs` is a single ~13,600-line file holding every
//! `EntryRow` construction — so while the type lived there,
//! `SafeLink("javascript:alert(1)")` compiled and rendered verbatim into an
//! `href`. An adversarial review demonstrated exactly that, five different ways.
//! Here the field is unreachable from `web.rs`, which is what makes "no bypass"
//! structural rather than aspirational.
/// A string that is safe to place in an `href`.
///
/// **Structural, not procedural — and that distinction is the whole point.** The
/// saved-record path takes an attacker-controlled URL (any atproto client can
/// write the record), and Askama escapes HTML metacharacters but NOT schemes, so
/// `javascript:` survives escaping intact.
///
/// The defence used to be "remember to call `net::safe_link` before assigning
/// this field". A cold review measured what that was worth: deleting the call
/// left **all 679 tests passing**, because every test either exercised the helper
/// directly or never rendered this row. The control was real and completely
/// unprotected.
///
/// So the field is no longer a `String`. There is no `From<String>`, no public
/// member, and neither constructor can carry a foreign URL into an `href`:
/// [`SafeLink::external`] performs the scheme check itself, and
/// [`SafeLink::entry`] takes an `i64` and a scope query rather than a string, so
/// it cannot be handed one.
;