Closed geeknik closed 3 years ago
@psmoros I think we have to re-write how we check the repo URL - will work with you on it
If you remove www from github repo url then it will be accepted
Assuming that huntr uses Regex, this would match the above URL and a few other edge cases:
^(https:\/\/)?(www\.)?github.com\/[a-zA-Z0-9\-\_]{1,}\/[a-zA-Z0-9\-\_]{1,}(\/)?$
Sorted and now live 🎉
This is more of an annoyance than anything functional. For example, at the top of
https://huntr.dev/bounties/1625486747136-riyadhalnur/node-base64-image/
, it says Code Injection in riyadhalnur/node-base64-image. It links towww.github.com
, which in and of itself isn't really an issue, however, if you right click and copy that link and then drop the link into the box athttps://huntr.dev/bounties/disclose/
, the page throws an exception and saysPlease enter a valid GitHub repository URL, including https://...