Re: Restrictions List Incomplete

Thomas Dickey <[email protected]> Sat, 25 Jul 2026 14:30:05 -0400
Newsgroups gmane.comp.web.lynx.devel
Message-ID <[email protected]>
--gJUYmzbLR65VnoGn
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Jul 25, 2026 at 02:13:37PM -0000, Tavis Ormandy wrote:
> I noticed an odd behaviour, maybe it's not intended.
>=20
> I was trying to use lynx to read articles in my terminal, but noticed
> google news redirects to a URL containing `:`, which lynx rejects:
>=20
> $ lynx -force_html -restrictions=3Dall 'https://news.google.com/rss/artic=
les/CBMiVEFVX3lxTE9OVnBXanNudE
> 5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnRFdGxMQk0yUTB=
ubGh6bUQ0YW5HVHJJSQ?oc=3D5'
> Alert!: Illegal redirection URL received from server!
>=20
> Okay, but I can see it works without the restrictions, so it must be one
> of the restrictions that `all` is enabling... but which one?
>=20
> So I tried with every restriction listed in the man page (except
> options_save, which is listed in the manual but lynx rejects)
>=20
> $ lynx -force_html -restrictions=3Dbookmark,bookmark_exec,change_exec_per=
ms,dired_support,disk_save,dotfiles,download,editor,exec,exec_frozen,extern=
als,file_url,goto,inside_ftp,inside_news,inside_rlogin,inside_telnet,jump,m=
ultibook,mail,news_post,outside_ftp,outside_news,outside_rlogin,outside_tel=
net,print,shell,suspend,telnet_port,useragent 'https://news.google.com/rss/=
articles/CBMiVEFVX3lxTE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWl=
FYaWN2aFBna1R3Wkd1WnRFdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5'

A more complete list can be printed using
	lynx -restrictions ?
=20
fwiw, there are a couple not listed in the manpage:

--- expected	2026-07-25 13:47:14.665828027 -0400
+++ actual	2026-07-25 13:47:50.389827687 -0400
@@ -1,6 +1,10 @@
+all
 bookmark
 bookmark_exec
 change_exec_perms
+chdir
+compileopts_info
+default
 dired_support
 disk_save
 dotfiles
@@ -16,9 +20,13 @@
 inside_rlogin
 inside_telnet
 jump
+lynxcfg_info
+lynxcfg_xinfo
+lynxcgi
 mail
 multibook
 news_post
+option_save
 outside_ftp
 outside_news
 outside_rlogin

but adding those (chdir, etc.) doesn't seem to trigger the problem.

> Except that works fine :)
>=20
> Maybe I don't understand how it's supposed to work!

the trace option may help.  The first case gives

HTTP: Picked up location 'https://news.google.com/rss/articles/CBMiVEFVX3lx=
TE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnR=
FdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en'
HTTP/1.0 302 Found
HTAccess:  status=3D399
HTAccess: 'https://news.google.com/rss/articles/CBMiVEFVX3lxTE9OVnBXanNudE5=
pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnRFdGxMQk0yUTBubG=
h6bUQ0YW5HVHJJSQ?oc=3D5' is a redirection URL.
HTAccess: Redirecting to 'https://news.google.com/rss/articles/CBMiVEFVX3lx=
TE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnR=
FdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en'

Alert!: Illegal redirection URL received from server!

User message: Illegal URL: https://news.google.com/rss/articles/CBMiVEFVX3l=
xTE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1Wn=
RFdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en

The second one says

HTTP: Picked up location 'https://news.google.com/rss/articles/CBMiVEFVX3lx=
TE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnR=
FdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en'
HTTP/1.0 302 Found
HTAccess:  status=3D399
HTAccess: 'https://news.google.com/rss/articles/CBMiVEFVX3lxTE9OVnBXanNudE5=
pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnRFdGxMQk0yUTBubG=
h6bUQ0YW5HVHJJSQ?oc=3D5' is a redirection URL.
HTAccess: Redirecting to 'https://news.google.com/rss/articles/CBMiVEFVX3lx=
TE9OVnBXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnR=
FdGxMQk0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en'
User message: Using https://news.google.com/rss/articles/CBMiVEFVX3lxTE9OVn=
BXanNudE5pMzFuT00tdC1ERGhJMXBmN2phb1BiMmJjbnBaWlFYaWN2aFBna1R3Wkd1WnRFdGxMQ=
k0yUTBubGh6bUQ0YW5HVHJJSQ?oc=3D5&hl=3Den-US&gl=3DUS&ceid=3DUS:en

so... the issue is detected right after the "Redirecting".

Referring to the source code, the "Illegal" message happens in

	src/LYGetFile.c

in a chunk beginning

		if (!HTPermitRedir &&
		    (url_type =3D=3D LYNXDOWNLOAD_URL_TYPE ||
		     url_type =3D=3D LYNXEXEC_URL_TYPE ||
		     url_type =3D=3D LYNXPROG_URL_TYPE ||

The HTPermitRedir variable might be set in

	WWW/Library/Implementation/HTRules.c

and is reset in LYGetFile.c if a redirect was done.

The redirected URL is https, and appears to be triggering this;

		     (no_goto_https &&
		      url_type =3D=3D HTTPS_URL_TYPE) ||

Revisiting the "?" option for printing the list of restrictions, I see
this in the print_restrictions code:

	    /* if "goto" is restricted, don't bother tell about its
	     * refinements
	     */

The table has this line:

    { "goto",		&no_goto,		CAN_ANONYMOUS_GOTO },

and the flag is compiled-in as "TRUE":

userdefs.h:1760:#define CAN_ANONYMOUS_GOTO		TRUE

Offhand, I don't see a way to have lynx print the whole table
(I suppose in this instance it would help to be able to do that).

--=20
Thomas E. Dickey <[email protected]>
https://invisible-island.net

--gJUYmzbLR65VnoGn
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEEGYgtkt2kxADCLA1WzCr0RyFnvgMFAmplAKkACgkQzCr0RyFn
vgP2Uwv/RHOjwScFlQyTZ3hor+tf6kZiM/KQTBW13kRdR13x/ZTmF7AtI4p4KRfl
PxLI1khG7gW/CERS8lblodfrxjBDuAsKjUqQ99U4jLh2RmhS7gYVts+ZAnEaF9xe
lulWXE2nv/tcpEnXCQ2TyZycPtolnVIOD6rnO0zpb8KEIoXJKduDf3MJ0JJUUk+y
zO7vl75ZWFbst1qqYtkS3FH7TFa2JoC84TczoiDro2PEP4E+DLLa3mIP9gT/vlvY
bAyx+o9oo2sJ0iH7sR5980aV+zYT3hdLqdlSWsdjiZsNPW/Doz/pYawgm4WUNuJH
2+S+K+cSWt71fUzt2mzW2zVMwSFY9/Wdlt4g+c1oDRrO01Vva5fBT0K6rPRFFpPB
XKb2QOdI3ksaL8ZP6XH0MOhAcUYYUGeM9KY7LVUfWIXX0Oqeq4rJdYI3rodl+q0x
qQiQjY8K4x5wgF7HmS4GytmsQP17/WNlvIEe2YWJhppUZUoDHWBi4Md8Y26yidYh
Gs/7PQDp
=dh6x
-----END PGP SIGNATURE-----

--gJUYmzbLR65VnoGn--