Draft implementation PR: https://github.com/badbundle/track-slash/pull/91
Description
Problem
Issue, project, sprint, and context Markdown converts any http or https image destination into a live <img> tag (internal/server/markdown.go:127-163, :220-237). The security test explicitly preserves this behavior for arbitrary external and SVG URLs.
Loading a description therefore causes each viewer's browser to contact an author-controlled server. HTML escaping prevents script injection, but it does not prevent network-level tracking.
Impact
A user with description-writing access can learn other viewers' IP address, user agent, approximate view time/frequency, and track them across descriptions using unique URLs. Browser referrer behavior may additionally disclose the track-slash origin, especially without an explicit Referrer-Policy.
Acceptance criteria
- Default external Markdown images to inert links/placeholders, or require an explicit user/admin opt-in before loading them.
- Continue rendering attached
object-Nimages from authenticated same-origin routes. - If proxying/caching is chosen instead, design explicit SSRF protections: scheme allow-list, DNS/IP revalidation, private/link-local/metadata address blocking, redirect limits, size/time limits, safe content sniffing, and cache isolation.
- Align CSP
img-srcand Referrer-Policy with the chosen behavior. - Add tests proving arbitrary external images do not generate automatic browser requests by default while normal external links remain usable.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.