Skip to content

fix: harden production network and dependency boundaries - #20

Merged
abla86 merged 3 commits into
mainfrom
fix/complete-hardening-2026-09-25
Sep 25, 2026
Merged

abla86 merged 3 commits into
mainfrom
fix/complete-hardening-2026-09-25

Conversation

@abla86

@abla86 abla86 commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Fix duplicate Vite plugin dependency, block private-network SSRF targets in live URL inspection, constrain GitHub repository identifiers, and bound remote HTML response sizes.

Copilot AI lite review requested due to automatic review settings September 25, 2026 20:35
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@abla86
abla86 merged commit 1ad0d9d into main Sep 25, 2026
5 checks passed
@abla86
abla86 deleted the fix/complete-hardening-2026-09-25 branch September 25, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved SSRF bypasses, response buffering, repository validation, and lockfile issues remain.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 4 High severity · 2 Medium severity

Open (6)
What changed in this PR

Hardens production network requests and dependency boundaries by adding SSRF protections, response-size limits, repository validation, and removing a duplicate Vite dependency.

Changes:

  • Adds DNS/IP and redirect safeguards for URL inspection.
  • Bounds remote response sizes.
  • Tightens GitHub repository identifiers.
  • Removes the duplicate Vite plugin dependency.
File Summary
server.ts Adds SSRF checks, response limits, and repository validation.
package.json Removes the duplicate Vite plugin dependency.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread server.ts
Comment on lines +652 to +654
return a === 10 || a === 127 || (a === 169 && b === 254)
|| (a === 172 && b >= 16 && b <= 31)
|| (a === 192 && b === 168);
Comment thread server.ts
Comment on lines +650 to +663
if (net.isIPv4(address)) {
const [a, b] = address.split('.').map(Number);
return a === 10 || a === 127 || (a === 169 && b === 254)
|| (a === 172 && b >= 16 && b <= 31)
|| (a === 192 && b === 168);
}
if (net.isIPv6(address)) {
return normalized === '::1'
|| normalized.startsWith('fc')
|| normalized.startsWith('fd')
|| normalized.startsWith('fe8')
|| normalized.startsWith('fe9')
|| normalized.startsWith('fea')
|| normalized.startsWith('feb');
Comment thread server.ts
Comment on lines +669 to +672
const resolved = await dns.lookup(hostname, { all: true });
if (resolved.length === 0 || resolved.some((entry) => isPrivateAddress(entry.address))) {
return res.status(400).json({ error: 'Private or local network targets are not allowed.' });
}
Comment thread server.ts
Comment on lines +669 to +672
const resolved = await dns.lookup(hostname, { all: true });
if (resolved.length === 0 || resolved.some((entry) => isPrivateAddress(entry.address))) {
return res.status(400).json({ error: 'Private or local network targets are not allowed.' });
}
Comment thread package.json
@@ -15,7 +15,6 @@
"dependencies": {
"@google/genai": "^2.4.0",
"@tailwindcss/vite": "^4.1.14",
Comment thread server.ts
Comment on lines 711 to +713
const htmlText = await response.text();
if (Buffer.byteLength(htmlText, 'utf8') > 2 * 1024 * 1024) {
return res.status(413).json({ success: false, url, httpStatus, latencyMs, contentType, verdict: 'unreachable', error: 'Response body too large.' });
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants