fix(security): harden YAML parsing, path traversal, and markdown links

- workflowSerialization: restrict YAML parser to core schema with no custom tags
- gitService: validate file paths stay within project directory before I/O
- chatMarkdown: allowlist URL protocols (https, http, mailto, anchors)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
David Kaya
2026-04-05 23:43:06 +02:00
co-authored by Copilot
parent b302ea5979
commit 059714326a
3 changed files with 26 additions and 5 deletions
+7 -1
View File
@@ -177,9 +177,15 @@ export function exportWorkflowDefinition(
}
}
const safeYamlOptions = {
schema: 'core' as const,
customTags: [] as [],
merge: false as const,
};
export function importWorkflowDefinition(content: string, format: 'yaml' | 'json'): WorkflowDefinition {
const parsed = format === 'yaml'
? parseYaml(content)
? parseYaml(content, safeYamlOptions)
: JSON.parse(content) as unknown;
return ensureValidWorkflow(coerceWorkflowDefinition(parsed));