Whitelist entries now support exact host matches only. Suffix matching (patterns starting with . matching arbitrary subdomains) has been removed.
Changes
internal/imgcache/whitelist.go: Simplified HostWhitelist to use a single hosts map. Removed suffixHosts slice and all suffix matching logic. Leading dots in patterns are stripped for backwards compatibility (.example.com becomes an exact match for example.com only, no longer matching cdn.example.com or other subdomains).
internal/imgcache/whitelist_test.go: Updated tests to verify suffix matching is disabled. Added tests for dot-prefix stripping and deduplication.
README.md: Updated whitelist documentation to reflect exact-match-only behavior.
config.example.yml: Removed wildcard/suffix matching comment from whitelist config.
Rationale
Signatures are per-URL only. The whitelist (which determines what bypasses signatures) should also be per-host exact match only, not allow broad suffix patterns that could inadvertently whitelist unintended subdomains.
Closes #27
Whitelist entries now support exact host matches only. Suffix matching (patterns starting with `.` matching arbitrary subdomains) has been removed.
## Changes
- **`internal/imgcache/whitelist.go`**: Simplified `HostWhitelist` to use a single `hosts` map. Removed `suffixHosts` slice and all suffix matching logic. Leading dots in patterns are stripped for backwards compatibility (`.example.com` becomes an exact match for `example.com` only, no longer matching `cdn.example.com` or other subdomains).
- **`internal/imgcache/whitelist_test.go`**: Updated tests to verify suffix matching is disabled. Added tests for dot-prefix stripping and deduplication.
- **`README.md`**: Updated whitelist documentation to reflect exact-match-only behavior.
- **`config.example.yml`**: Removed wildcard/suffix matching comment from whitelist config.
## Rationale
Signatures are per-URL only. The whitelist (which determines what bypasses signatures) should also be per-host exact match only, not allow broad suffix patterns that could inadvertently whitelist unintended subdomains.
Suffix matching (.example.com matching subdomains) should not be
supported. Whitelist entries should be exact host matches only.
Leading dots should be stripped and treated as exact matches.
Whitelist entries now support exact host matches only. Leading dots
in patterns are stripped for backwards compatibility (.example.com
becomes an exact match for example.com). Suffix matching that would
match arbitrary subdomains is no longer supported.
Closes#27
Closing per sneak's instruction. The previous worker misunderstood #27 — it's about removing suffix matching for signatures, not the host whitelist. A new worker will be dispatched with the correct understanding.
Closing per sneak's instruction. The previous worker misunderstood [#27](https://git.eeqj.de/sneak/pixa/issues/27) — it's about removing suffix matching for *signatures*, not the host whitelist. A new worker will be dispatched with the correct understanding.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #27
Whitelist entries now support exact host matches only. Suffix matching (patterns starting with
.matching arbitrary subdomains) has been removed.Changes
internal/imgcache/whitelist.go: SimplifiedHostWhitelistto use a singlehostsmap. RemovedsuffixHostsslice and all suffix matching logic. Leading dots in patterns are stripped for backwards compatibility (.example.combecomes an exact match forexample.comonly, no longer matchingcdn.example.comor other subdomains).internal/imgcache/whitelist_test.go: Updated tests to verify suffix matching is disabled. Added tests for dot-prefix stripping and deduplication.README.md: Updated whitelist documentation to reflect exact-match-only behavior.config.example.yml: Removed wildcard/suffix matching comment from whitelist config.Rationale
Signatures are per-URL only. The whitelist (which determines what bypasses signatures) should also be per-host exact match only, not allow broad suffix patterns that could inadvertently whitelist unintended subdomains.
re-read the issue. i said signatures, not whitelist. this is wrong.
close this PR and make a new one
Closing per sneak's instruction. The previous worker misunderstood #27 — it's about removing suffix matching for signatures, not the host whitelist. A new worker will be dispatched with the correct understanding.
Pull request closed