Skip to content

Security/client http redirect validation#26401

Open
YoussefAhmed256 wants to merge 3 commits intojenkinsci:masterfrom
YoussefAhmed256:security/client-http-redirect-validation
Open

Security/client http redirect validation#26401
YoussefAhmed256 wants to merge 3 commits intojenkinsci:masterfrom
YoussefAhmed256:security/client-http-redirect-validation

Conversation

@YoussefAhmed256
Copy link

@YoussefAhmed256 YoussefAhmed256 commented Mar 4, 2026

Fixes #26387 >
Implement URL validation and security checks in ClientHttpRedirect by restricting redirects to HTTP/HTTPS and relative paths only.
Added a null check for redirectUrl to prevent invalid usage and fail fast.
Also added a dedicated test class with unit tests covering allowed and blocked redirect scenarios.

Testing done

Screenshots (UI changes only)

Before

After

image

i tested it with script because there is no function that uses this class yet

Proposed changelog entries

/label skip-changelog

Proposed changelog category

/label bu

Proposed upgrade guidelines

N/A

Submitter checklist

  • The issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples). Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • UI changes do not introduce regressions when enforcing the current default rules of Content Security Policy Plugin. In particular, new or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

@mention

Before the changes are marked as ready-for-merge:

Maintainer checklist

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, be a Bug or Improvement, and either the issue or pull request must be labeled as lts-candidate to be considered.

@welcome
Copy link

welcome bot commented Mar 4, 2026

Yay, your first pull request towards Jenkins core was created successfully! Thank you so much!

A contributor will provide feedback soon. Meanwhile, you can join the chats and community forums to connect with other Jenkins users, developers, and maintainers.

@comment-ops-bot comment-ops-bot bot added the skip-changelog Should not be shown in the changelog label Mar 4, 2026
@YoussefAhmed256
Copy link
Author

@MarkEWaite take a look

@MarkEWaite
Copy link
Contributor

@MarkEWaite take a look

It will be two weeks or more before I look at it. I'm on vacation for the next week. When I return, I have other tasks that are higher priority.

@timja timja requested a review from daniel-beck March 6, 2026 07:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Should not be shown in the changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Restrict ClientHttpRedirect to http/https URLs

2 participants