Skip to content

[Aikido] Enforce firewall decisions at Starlette app entry point to prevent bypass - #748

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137921942-fydm
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137921942-fydm

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a critical firewall bypass vulnerability in Starlette mounted ASGI applications where firewall decisions were not being enforced before dispatching requests to mounted or custom ASGI callables. The fix introduces a firewall_enforced flag that is initialized in the request context and enforced at the application entry point before any handler dispatch occurs. Changes were made to aikido_zen/context/__init__.py to initialize the flag, aikido_zen/sources/starlette/starlette_routing.py to enforce firewall decisions early in the request lifecycle, and corresponding test files to validate the new behavior.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811708263
HIGH
The patched Starlette.__call__ establishes request context and invokes only request_handler(stage="init"); the blocking pre_response stage is reached only from the wrapper installed through starlette.routing.request_response. Starlette mounts and custom ASGI applications are dispatched directly as ASGI callables rather than being constructed through that route factory. Therefore, under the automatic Starlette integration, a request targeting such an application does not receive the configured firewall decision before dispatch. The separately defined ASGI middleware is not installed by protect(), so it is not an automatic compensating boundary. This is an access-control enforcement bypass for mounted/custom ASGI handlers.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant