The four SonarCloud findings #238 kept. The other 34 are dismissed on the dashboard with the reasons from that issue, so this leaves it at zero.
Off-site redirect (gosecurity:S5146, BLOCKER)
net/http fills URL.Scheme and URL.Host from an absolute-form request
line, which RFC 7230 requires a server to accept. The #233 trailing-slash
handler copies r.URL, trims the slash and redirects to u.String(), so
the host came along:
"GET /cmc/ HTTP/1.1" -> 301 "/cmc" "GET http://evil.example/cmc/ HTTP/1.1" -> 301 "http://evil.example/cmc"
Cleared after the pattern lookup rather than before it, so matching is
untouched either way - ServeMux matches host patterns on the Host
header, not on `URL.Host`. The protocol-relative case was already covered:
ServeMux's own cleanPath rewrites a leading // before the fallback
runs, and TestTrailingSlashRedirects has asserted that since #153.
A browser only sends absolute form to a proxy, so nothing reaches this through one directly; what it reaches is anything in front that forwards the request line as it arrived.
The test case added to TestTrailingSlashRedirects fails on the parent
commit with Location "http://evil.example/cmc", want "/cmc".
http.ReadRequest also takes Host from the URL, which sends the request
to the pages router; it is pinned back to the site host so the case stays
a test of the forge handler.
autofocus (Web:S9379 ×3)
Removed from globalsearch.html, search.html and register.html, where
it moved focus past the heading, the result count and the global search
page's filter navigation. The form is the first interactive thing on each
page, so the first Tab reaches it regardless.
layout.html's diff line-comment textarea keeps its autofocus and is
dismissed as won't fix instead: that form renders only after the reader
asks for it on a specific line, and with no JavaScript autofocus is the
only thing carrying focus across the reload.
Verified
go build ./..., go vet and the unit tests of internal/httpd and
internal/web are green; the e2e suite is CI's.