oc · docs
docs / documentation

@orangecheck/vault-core


@orangecheck/vault-core / registrableDomain

Function: registrableDomain()

function registrableDomain(host: string): string;

Defined in: vault-core/src/origin.ts:126

The registrable domain (eTLD+1) of a hostname — mail.example.co.uk → example.co.uk.

READ THIS BEFORE TRUSTING IT. Determining eTLD+1 correctly requires the Public Suffix List; this is a hand-maintained approximation, and the approximation fails in the LOOSE direction — an unknown multi-label suffix is treated as a registrable domain rather than as a suffix.

That is a credential-disclosure bug, not a cosmetic gap. With github.io absent from the set below, alice.github.io and attacker.github.io both reduce to github.io, so matchEntryToPage answers 'registrable' and the vault offers alice's credential on the attacker's page. The same held for vercel.app, pages.dev, herokuapp.com, blogspot.com and every second-level ccTLD outside the list. The twelve entries that WERE listed behaved correctly, which is exactly why a test written against the list passed.

The docstring here used to claim it "falls back to the full host when the suffix is unknown (stricter, never looser)". It did not: it returned the last two labels. The claim described the property this function should have and the code did the opposite.

The set now covers the shared-hosting suffixes — where every customer is a sibling subdomain and the exposure is real — plus the common ccTLD second levels. It is still an approximation. A complete fix is the PSL; until then, treat 'registrable' as a hint and prefer 'exact' for anything sensitive.

Parameters

ParameterType
hoststring

Returns

string