Fix #78: webhook delivery SSRF hardening #88
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!88
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-78"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #78.
Scope mapping: the issue names internal/notify/webhooks.go + internal/repoimport/url.go, which exist only in unmerged feature worktrees, not on origin/main. The live SSRF surface on main is identical in shape: internal/events/sink.go used a default http.Client (up to 10 cross-scheme/scheme-downgrading redirects, Go forwarding X-Walgit-Signature + body cross-host) with no IP screening. This PR hardens that sink.
Fix (stdlib only, law 1; wire contract + admin-gating + delivery semantics unchanged):
Tests: table-driven httptest — cross-host redirect reaches target 0 times (no signature/body leak); redirect-to-169.254 refused; same-host redirect refused; 9 private-literal URLs refused fast; dial-layer unit tests; 40-case blocked-IP table incl. mapped-v6. gofmt/vet clean, -race green, internal/events coverage 97.5% (gate ≥95%), e2e TestE2E_EventsWebhookDelivery passes against the real binary (loopback path intact).
isPrivateIPrange gaps (verify against new egress table first) #96isPrivateIPrange gaps (verify against new egress table first) #96