Pascal THUET
|
5601830ba3
|
harden: bound HTTP reads and enforce strict redirects (#3140)
* harden: bound HTTP reads and enforce strict redirects
Add a shared _download_security module (read_response_limited,
is_https_or_localhost_http, size constants) and route the GitHub release
and Azure DevOps token network reads through bounded reads so an oversized
response can't exhaust memory.
Add a strict_redirects mode to authentication.open_url: the redirect handler
now rejects any redirect whose target isn't HTTPS (or HTTP to localhost),
composing with the existing per-hop redirect_validator and auth-stripping.
The Azure DevOps token POST is routed through that handler so a 307/308
cannot forward the client_secret body to a non-HTTPS host.
Assisted-by: Codex (model: GPT-5, autonomous)
* test: align HTTP fakes with bounded reads
Assisted-by: Codex (model: GPT-5, autonomous)
* fix: tolerate invalid token response encoding
Assisted-by: Codex (model: GPT-5, autonomous)
* test: align GHES fakes with bounded reads
Assisted-by: Codex (model: GPT-5, autonomous)
* test: reuse shared upgrade HTTP response helper
Assisted-by: Codex (model: GPT-5, autonomous)
* fix: include rejected redirect target in error
Assisted-by: Codex (model: GPT-5, autonomous)
* fix: enforce strict redirects by default
Assisted-by: Codex (model: GPT-5, autonomous)
* fix: close redirect credential and SSRF gaps
Assisted-by: Codex (model: GPT-5, autonomous)
|
2026-07-22 11:08:32 -05:00 |
|