fix(farm): enforce secure API request boundaries#354
Closed
SUaDtL wants to merge 2 commits into
Closed
Conversation
Record the focused SD-02 review as active before producing its durable security evidence.
Validate every fetch-producing seam, refuse automatic redirects, and prevent configured or provider-controlled secrets from entering diagnostics. Closes #353 CHANGELOG: Farm API requests now fail closed across redirects, direct-call seams, and credential-bearing diagnostics.
Collaborator
Author
|
Superseded by #313, the single hackathon review surface. This PR's recorded head and changes are represented in #313's exact 16-PR / 29-commit / 126-path source manifest. PR #313 passed final exact-head CI at commit 6173b1d and remains open and unmerged. Closing this source PR to avoid parallel review; please continue review and discussion on #313. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the SD-02 farm base-URL review and fixes the transport defects it exposed.
farm.jsbundle and records the focused review under.codearbiter/reports/.Why
The original guard protected CLI configuration, but direct exported calls could bypass it. Default fetch redirect handling could also forward POST bodies to an unvalidated destination. Credential-bearing URLs and provider-controlled bodies could enter logs, retry prompts, or reports.
Tradeoff (Level 2 security boundary): redirects now fail closed instead of being followed, and diagnostics identify only the parsed origin. This preserves the transport and secret-handling guarantees in ADR-0003 and
.codearbiter/security-controls.md.Verification
npm test: 198 passednpm run typecheck: passednpm run build: passed; second build produced the same SHA-256npm audit --omit=dev --audit-level=critical: 0 vulnerabilitiesCloses #353