Unfortunately, the "sensible defaults" don't seem to check input URLs correctly and allow file:// URLs.
Just try ?url=file:///etc/passwd on the demo instance.
That seems to be a quite common issue with services like this built on generic libraries.
Just try ?url=file:///etc/passwd on the demo instance.
That seems to be a quite common issue with services like this built on generic libraries.
window.location.href = 'file:///' will return console error: "Not allowed to load local resource"
It might be better to blacklist file:// rather than trying to have a comprehensive whitelist.
{"status":400,"statusText":"Bad Request","errors":[{"field":["url"],"location":"query","messages":["\"url\" must be a valid uri with a scheme matching the http|https pattern"],"types":["string.uriCustomScheme"]}]}