Privacy: proxy external Note images instead of loading third-party origins #766

Open
opened 2026-10-02 13:10:02 +00:00 by kayg · 1 comment
Owner

Browser audit follow-up from #663. Audited dev: c4a61e8cf0.

B3 — Notes load external images in the browser

Status: confirmed by code trace; duplicate search complete; filed by sec-browser audit.
Merge class: privacy follow-up; no script execution claim.

apps/web/src/lib/notes/editorHost.ts:71 passes external HTTP(S) images to
the browser. NoteImageView.svelte:39 uses the result as an image source.
crates/calternal-server/src/security.rs:121 permits all HTTPS image
origins. Opening an imported Note can disclose IP, request time and browser
metadata to an image origin. The User does not need to click a link.
Mail's consent-only direct image loads are already owned by #726; do not
create a second Mail image-proxy issue.

Fix: reuse the server image-proxy policy from #726 for Notes. Bound type,
size and time; check public destinations and redirect hops; strip cookies
and Referer. Make protection silent, as the owner requires.

Test: with a benign synthetic remote image, assert no external browser
request and no outbound cookies or Referer. Keep local attachments working.

Evidence is a defensive code trace; no production access or hostile payload was used.

Browser audit follow-up from #663. Audited dev: c4a61e8cf090170f35b1bed3350d9de20c83ecd5. ### B3 — Notes load external images in the browser Status: confirmed by code trace; duplicate search complete; filed by sec-browser audit. Merge class: privacy follow-up; no script execution claim. `apps/web/src/lib/notes/editorHost.ts:71` passes external HTTP(S) images to the browser. `NoteImageView.svelte:39` uses the result as an image source. `crates/calternal-server/src/security.rs:121` permits all HTTPS image origins. Opening an imported Note can disclose IP, request time and browser metadata to an image origin. The User does not need to click a link. Mail's consent-only direct image loads are already owned by #726; do not create a second Mail image-proxy issue. Fix: reuse the server image-proxy policy from #726 for Notes. Bound type, size and time; check public destinations and redirect hops; strip cookies and Referer. Make protection silent, as the owner requires. Test: with a benign synthetic remote image, assert no external browser request and no outbound cookies or Referer. Keep local attachments working. Evidence is a defensive code trace; no production access or hostile payload was used.
Author
Owner

The pinned job/mailhtml-726 branch has no server image-proxy route yet; the current Notes image resolver passes remote HTTP(S) URLs to the browser. I am adding one authenticated shared /api/v1/images/proxy route with the existing pinned public-endpoint resolver, redirect-hop validation, no forwarded Cookie or Referer, and byte, type, time and concurrency bounds. Notes will use it. Please have #726 consume this same route for Mail images.

The pinned `job/mailhtml-726` branch has no server image-proxy route yet; the current Notes image resolver passes remote HTTP(S) URLs to the browser. I am adding one authenticated shared `/api/v1/images/proxy` route with the existing pinned public-endpoint resolver, redirect-hop validation, no forwarded Cookie or Referer, and byte, type, time and concurrency bounds. Notes will use it. Please have #726 consume this same route for Mail images.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#766
No description provided.