Skip to content

fix(lib-vuetify): only follow http(s) chat links, open other origins in a new tab - #72

Merged
albanm merged 1 commit into
mainfrom
fix-agent-link-hardening
Sep 29, 2026
Merged

albanm merged 1 commit into
mainfrom
fix-agent-link-hardening

Conversation

@albanm

@albanm albanm commented Sep 29, 2026

Copy link
Copy Markdown
Member

Harden how links written by the model in chat are followed:

  • The host (lib-vuetify) only acts on http(s) links. javascript:, data:, vbscript: and malformed hrefs are ignored instead of being assigned to window.location.
  • Links to another origin now open in a new tab (noopener,noreferrer) instead of replacing the host page. Same-origin links still use in-SPA navigation, or a full page load when no route matches.
  • The evaluator chat's link handler gets the same http(s) filter.

Why: the href is model output, so a page or tool result can influence it. Before this change, a javascript: link would run in the host page with the user's session, and a cross-origin link could silently replace the host page with a look-alike.

Heads-up:

  • Behavior change: cross-origin links no longer navigate the host page. This includes links to sibling services on another subdomain.
  • window.open runs in the host's postMessage handler, relying on the click's user activation reaching the parent frame. Check that popup blockers allow it in Firefox and Safari.
  • NavDecision.spa is replaced by action. link-utils is not re-exported from the package index, so only deep imports are affected.

…in a new tab

The navigate handler assigned the raw href of a link clicked in the chat to
the host page's location: a javascript: URL (its origin is "null", so it took
the external branch) would run in the host page with the user's session, and
an off-site link planted in the conversation replaced the host page in one
click. Only sanitize-html in the chat markdown stood in the way.

Anything but an http(s) URL is now ignored, and another origin opens in a new
tab without an opener. The evaluator page gets the same scheme check.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the fix label Sep 29, 2026
@albanm
albanm merged commit 66f29b3 into main Sep 29, 2026
4 checks passed
@albanm
albanm deleted the fix-agent-link-hardening branch September 29, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant