-
Notifications
You must be signed in to change notification settings - Fork 3.6k
fix(security): harden findings — path traversal, SSRF, IDOR, file auth, credential access #4571
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
17 commits
Select commit
Hold shift + click to select a range
398dc65
fix(security): harden HIGH deepsec findings across multiple attack su…
waleedlatif1 7b84a79
fix(security): eliminate workspace env lost-update race with atomic J…
waleedlatif1 7b6e43d
fix(security): address audit findings from security fix review
waleedlatif1 2d86b7b
fix(security): address PR review comments and harden deepsec fixes
waleedlatif1 ba4738b
fix(workflows): fix VariableType assignment in admin workflow import …
waleedlatif1 7e1104e
fix(a2a): handle Request objects in pinnedFetch URL extraction
waleedlatif1 b7d57af
fix(security): extract shared file-access guard; merge workspace/moth…
waleedlatif1 1fdb0df
fix(security): advisory lock for env first-insert race; handle all Bo…
waleedlatif1 feea2e3
chore: remove inline comment from advisory lock
waleedlatif1 e1a37d7
fix(security): remove stray comment; narrow credentialType to literal…
waleedlatif1 5719fd6
fix(security): add credentialId validation to wealthbox oauth route; …
waleedlatif1 988ce33
fix(security): stream A2A response body to unblock SSE; keep text/jso…
waleedlatif1 e56cb1c
fix(security): resolve credentialId guard on OneDrive, use assertTool…
waleedlatif1 7152789
fix(security): handle string[][] HeadersInit format in pinnedFetch
waleedlatif1 5940ed2
fix(security): keep abort listener alive during body streaming; clean…
waleedlatif1 0073513
chore: remove extraneous inline comment
waleedlatif1 31e97df
fix(security): cleanup abort listener when maxResponseBytes limit is …
waleedlatif1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.