Skip to content

Commit 160b151

Browse files
committed
add security note about accessing urls
1 parent 775b578 commit 160b151

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

specs/jsonschema-core.md

+6
Original file line numberDiff line numberDiff line change
@@ -1990,6 +1990,12 @@ A malicious schema author could place executable code or other dangerous
19901990
material within a `$comment`. Implementations MUST NOT parse or otherwise take
19911991
action based on `$comment` contents.
19921992

1993+
When encoutering an IRI that is also a valid URL, implementations SHOULD NOT
1994+
presume a network operation should be performed. Implementations which have
1995+
access to the internet SHOULD default to operating offline. Network operations
1996+
should be limited to hypermedia APIs and similar applications where this risk
1997+
already exists and is built into the architecture.
1998+
19931999
## IANA Considerations
19942000

19952001
### `application/schema+json`

0 commit comments

Comments
 (0)