trackslash
TRACK-12 P3

Prevent external Markdown images from acting as tracking pixels

0
All issues

Description

Problem

Issue, project, sprint, and context Markdown converts any http or https image destination into a live <img> tag (internal/server/markdown.go:127-163, :220-237). The security test explicitly preserves this behavior for arbitrary external and SVG URLs.

Loading a description therefore causes each viewer's browser to contact an author-controlled server. HTML escaping prevents script injection, but it does not prevent network-level tracking.

Impact

A user with description-writing access can learn other viewers' IP address, user agent, approximate view time/frequency, and track them across descriptions using unique URLs. Browser referrer behavior may additionally disclose the track-slash origin, especially without an explicit Referrer-Policy.

Acceptance criteria

  • Default external Markdown images to inert links/placeholders, or require an explicit user/admin opt-in before loading them.
  • Continue rendering attached object-N images from authenticated same-origin routes.
  • If proxying/caching is chosen instead, design explicit SSRF protections: scheme allow-list, DNS/IP revalidation, private/link-local/metadata address blocking, redirect limits, size/time limits, safe content sniffing, and cache isolation.
  • Align CSP img-src and Referrer-Policy with the chosen behavior.
  • Add tests proving arbitrary external images do not generate automatic browser requests by default while normal external links remain usable.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1