Repository navigation
fix(docs): add /terms and /privacy redirects for footer links - #29667
ashishgit4 wants to merge 3 commits into
Conversation
|
📊 PR Size: size/L
|
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request updates the documentation routing to improve accessibility for common footer links. By adding redirects for /terms and /privacy, users are correctly routed to the existing Terms of Service and Privacy documentation. Additionally, the PR includes a local testing script to ensure these redirects function as expected and cleans up unused snapshot files. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request adds redirects for /terms and /privacy to /docs/resources/tos-privacy in docs/redirects.json, introduces a redirect markdown file docs/terms.md, removes several unused SVG assets, and adds a local test server test-redirects.js to verify the redirect logic. A high-severity path traversal vulnerability was identified in the test server's serveMarkdownAsHtml function, where untrusted URL paths are resolved without sanitization. It is recommended to resolve and validate the paths against the docsRoot directory to prevent unauthorized file access.
| function serveMarkdownAsHtml(filePath, res) { | ||
| const docsRoot = path.join(__dirname, 'docs'); | ||
| const fullPath = path.join(docsRoot, filePath + '.md'); | ||
| const indexPath = path.join(docsRoot, filePath, 'index.md'); | ||
| const mdPath = fs.existsSync(fullPath) ? fullPath | ||
| : fs.existsSync(indexPath) ? indexPath | ||
| : null; |
There was a problem hiding this comment.
The filePath parameter is constructed from the request URL pathname and passed directly to path.join without sanitization. This allows a path traversal attack (e.g., using .. segments) to access files outside the docs directory.
To prevent this, resolve the paths using path.resolve and verify that they start with the resolved docsRoot directory.
function serveMarkdownAsHtml(filePath, res) {
const docsRoot = path.resolve(__dirname, 'docs');
const fullPath = path.resolve(docsRoot, '.' + filePath + '.md');
const indexPath = path.resolve(docsRoot, '.' + filePath, 'index.md');
if (!fullPath.startsWith(docsRoot) || !indexPath.startsWith(docsRoot)) {
res.writeHead(403, { 'Content-Type': 'text/plain' });
res.end('403: Access Denied');
return;
}
const mdPath = fs.existsSync(fullPath) ? fullPath
: fs.existsSync(indexPath) ? indexPath
: null;References
- Sanitize file paths extracted from untrusted sources to prevent path traversal (
..), null byte injection (0), and other vulnerabilities.
Summary
Fixes the non-clickable Google Developers link displayed in the footer of the Gemini CLI website.
Details
The Google Developers link/logo at the bottom of https://geminicli.com/ is displayed as part of the website footer, but clicking it does not navigate to the intended Google Developers destination.
This change makes the footer element a proper clickable link so users can navigate to the Google Developers website.
Related Issues
Fixes #YOUR_ISSUE_NUMBER
How to Validate
Pre-Merge Checklist