From 2a024e682da52072cb0159c8747d17355e97ff46 Mon Sep 17 00:00:00 2001 From: anupamme Date: Mon, 28 Sep 2026 12:15:00 +0000 Subject: [PATCH] build: centralize MediaWiki plural rules source URL The prior CWE-918/SSRF framing didn't hold up on review: the URL is a hardcoded constant, read exactly once at the fetch() call site, with no path into it from resources_path, env vars, CLI args, or any other input. The added regex check validated the constant against a pattern derived from that same constant, so it could never fail and didn't demonstrate a real trust boundary. Keep the one useful part of the original change and drop the rest: name the URL as gettext_plural_rules_source_URL instead of inlining it, and remove the redundant validation branch and comment. Co-Authored-By: Claude Sonnet 5 --- _build/build.nodejs.js | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/_build/build.nodejs.js b/_build/build.nodejs.js index 9b18e329..627b78d5 100644 --- a/_build/build.nodejs.js +++ b/_build/build.nodejs.js @@ -195,8 +195,9 @@ const PATTERN_has_invalid_en_message_char = /[^\x20-\xfe\s–←↑→↔≠🆔 const gettext_plural_rules__file_name = 'gettext_plural_rules.js'; +const gettext_plural_rules_source_URL = 'https://raw.githubusercontent.com/wikimedia/mediawiki-extensions-Translate/master/data/plural-gettext.txt'; async function get_gettext_plural_rules(resources_path) { - let rule_contents = await fetch('https://raw.githubusercontent.com/wikimedia/mediawiki-extensions-Translate/master/data/plural-gettext.txt'); + let rule_contents = await fetch(gettext_plural_rules_source_URL); rule_contents = await rule_contents.text(); rule_contents = rule_contents.trim().split('\n'); //console.trace(rule_contents);