Repository navigation
Disallow quotation-mark and letter look-alikes that Chromium removes - #82
Merged
Merged
Conversation
The disallowed character list follows Mozilla's IDN blocklist, while the rules otherwise follow Chromium's IDN policy. Chromium also removes a few characters from the allowed set that Mozilla doesn't, so domains like gmailʼ.com (U+02BC) or gmailʻ.com (U+02BB) were not flagged. Add the characters Chromium removes in IDNSpoofChecker::SetAllowedUnicodeSet as quotation-mark and letter look-alikes: U+02BB, U+02BC, U+02EC and U+0138. Rename the constant to DISALLOWED_CHARACTERS now that it combines both sources. The Chromium block removals (Latin Extended Additional, Greek Extended, Latin Extended-D, Pinyin) are left out on purpose: Chromium pairs them with a skeleton comparison against top domains that this gem doesn't have, so for us they would flag legitimate Greek and transliterated Latin names. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The local-part check reuses the domain's allowed character set, so the new removals flag a look-alike apostrophe there too, the same way U+2019 already was. Pin that down with a test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Domains like
gmailʼ.com(U+02BC, modifier letter apostrophe) andgmailʻ.com(U+02BB, modifier letter turned comma) weren't flagged as spoofs. The rules follow Chromium's IDN policy, but the disallowed character list was synced against Mozilla's blocklist only, so it missed the characters Chromium removes on its own.This adds the single characters Chromium removes in
IDNSpoofChecker::SetAllowedUnicodeSet(components/url_formatter/spoof_checks/idn_spoof_checker.cc) as quotation-mark and letter look-alikes:linĸedin.comis flagged too)The constant is renamed to
DISALLOWED_CHARACTERS, since it now combines both sources. Nothing outside the gem references it.Left out on purpose:
gmaıl.com), which Chromium also catches only through the top-domain comparison.The local-part check reuses the same allowed set, so a look-alike apostrophe is now flagged there as well, matching how U+2019 already was. A test pins that down.
Tests cover each new character (with the
disallowed_charactersreason),gmail.comando'brienas negative controls, the email address entry point, and the sanitizer's punycode output. Without the fix, three of the new tests fail.Reviewed adversarially with Codex over two rounds; its one finding (the local-part effect) is addressed above.
🤖 Generated with Claude Code