eliziff hardens court search and PDF handling
A small security pass closes two routes by which trusted legal-research workflows could be turned against their users.
eliziff has tightened how the fork follows CourtListener search results, preventing a manipulated next-page link from sending an authentication token to an untrusted destination.
- Court search pagination now stays within approved CourtListener origins, protecting credentials while users move through results.
- PDF viewing no longer permits a riskier form of in-browser code compilation when opening untrusted documents.
Neither change alters the research experience on its face. It makes the surrounding plumbing less willing to trust links and files simply because they arrived in a familiar workflow.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?