✨(frontend) detect text link in html body and warn user before redirect (#744)

Parse sanitized html before rendering to detect links that are just raw text then
transform them into anchor.
Furthermore, for security purpore, we catch event when a user clicks on a link then
display a confirmation modal displaying the real link.

Co-authored-by: Valentin Regnault <valentinregnault22@gmail.com>
This commit is contained in:
Jean-Baptiste PENRATH
2026-07-09 14:12:09 +02:00
committed by GitHub
co-authored by Valentin Regnault
parent 983df0fe6f
commit 39f2d9ca98
21 changed files with 652 additions and 26 deletions
+9
View File
@@ -299,6 +299,14 @@
"description": "Whether external images should be proxied",
"readOnly": true
},
"MESSAGE_TRUSTED_LINK_DOMAINS": {
"type": "array",
"items": {
"type": "string"
},
"description": "Hostnames whose external links skip the redirect confirmation modal (a leading *. wildcard also matches subdomains)",
"readOnly": true
},
"FEATURE_MAILDOMAIN_CREATE": {
"type": "boolean",
"readOnly": true
@@ -398,6 +406,7 @@
"MAX_RECIPIENTS_PER_MESSAGE",
"MAX_TEMPLATE_IMAGE_SIZE",
"IMAGE_PROXY_ENABLED",
"MESSAGE_TRUSTED_LINK_DOMAINS",
"FEATURE_MAILDOMAIN_CREATE",
"FEATURE_MAILDOMAIN_MANAGE_ACCESSES",
"FEATURE_THREAD_SPLIT",