From 1328d912e4f7469db216e97d797e91ab14c6ae58 Mon Sep 17 00:00:00 2001 From: tomfuertes Date: Fri, 1 May 2026 09:57:47 -0500 Subject: [PATCH] security: drop pbs.twimg.com hotlink in admin UI MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The header `` in templates/index.html pointed at https://pbs.twimg.com/profile_images/.../TX7TW-Mp_400x400.jpg. That has three problems: 1. Privacy leak — every load of the admin UI sent a request to Twitter's CDN, disclosing the visitor's IP and the fact that they administer this Hermes instance. 2. Availability — Twitter can rotate or remove the image at any time without notice; the admin header would 404. 3. Hotlink to a third-party CDN — bandwidth use is on someone else's account and outside our control. Replace with an inline SVG mark (a stylized "H" with two small wing flourishes, in the existing brand accent #6272ff on a dark rounded-square background). Inline SVG instead of a data URI keeps the markup readable and avoids URL-encoding the `#` in the color value. Considered alternatives: - Self-host the original JPEG: removes the leak but keeps a bitmap dependency for a 28px header glyph, and we'd need a static-file route in the Starlette app. - Bundled-asset data URI: same effect as inline SVG but harder to inspect/restyle. Inline SVG is the lowest-overhead option and adds zero new dependencies. After this change, `grep -rn 'twimg\|profile_images' templates/ server.py` returns empty. --- templates/index.html | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/templates/index.html b/templates/index.html index 7c82f5c..3c23956 100644 --- a/templates/index.html +++ b/templates/index.html @@ -685,8 +685,13 @@