[1.196.0] — 2026-08-14
Fixed (security) — the Workday adapter validates an api endpoint by its hostname, not a substring.
Fixed
- A
portals.ymlWorkdayapi:value is now accepted only when its hostname ismyworkdayjobs.com(or a.myworkdayjobs.comsubdomain). The old check was a substring match, so any URL that merely contained the string — e.g.https://evil.com/?x=myworkdayjobs.comorhttps://myworkdayjobs.com.evil.com/…— passed and would have been handed back as the fetchable endpoint. Real Workday endpoints are unaffected. (Reported by CodeQL, #443.)
Notes
- New
isWorkdayApi()parses the URL and checks the host inserver/lib/portals/adapters/workday.mjs; used by bothmatches()andbuildEndpoint().tests/workday-adapter-endpoint.test.mjs(+1). Suite: 2522.