# The use of "non" URLs on the ToS page

**URL:** <https://meta.discourse.org/t/the-use-of-non-urls-on-the-tos-page/211925>\
**Category:** Bug\
**Created:** [December 13, 2021, 6:19am UTC](https://meta.discourse.org/t/the-use-of-non-urls-on-the-tos-page/211925 "2021-12-13T06:19:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![LogoiLab](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/logoilab/32/243371_2.png) [@LogoiLab](https://meta.discourse.org/u/LogoiLab)\
**Post date:** [December 13, 2021, 6:19am UTC](https://meta.discourse.org/t/the-use-of-non-urls-on-the-tos-page/211925/1 "2021-12-13T06:19:42Z")

</div>

I have found a potentially concerning issue with the Terms Of Service Page on all discourse installs (including `try.discourse.org`).

The ToS section **7. Content Posted on Other Websites** contains links to `non-currentdomain.tld` These links are clickable because they are parsed just like any other post.

This allows for domain-squatting unregistered `non-currentdomain.tld` in some cases. A good example of this is `https://forum.openwrt.org/tos#5`

As a proof of point, I have registered [non-openwrt.org](http://non-openwrt.org).

You can see my “detailed” write-up here: [ComputeCode - Non-OpenWrt](https://computeco.de/posts/2021-12-12-non-openwrt.html)

I did not see this bug as worthy of a security bounty. But if you would like this submitted as one please let me know.

---

<div class="post-metadata">

**Author:** ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)\
**Post date:** [December 13, 2021, 6:54am UTC](https://meta.discourse.org/t/the-use-of-non-urls-on-the-tos-page/211925/2 "2021-12-13T06:54:05Z")

</div>

Can’t repro this on a new install, Looks like this is only available on Pre-GDPR era sites that were set up with old privacy policy and terms of service templates.
