mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
* fix: render GitHub-hosted images in PR descriptions on reviews page PR description images hosted on GitHub (user-attachment uploads and *.githubusercontent.com) render broken on the reviews page because private-repo attachments require GitHub auth the browser session lacks. Add an authenticated backend image proxy (host-allowlisted to guard against SSRF) and route those image URLs through it from the reviews UI. Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> * fix: harden PR image proxy (IDOR, SVG XSS, unbounded buffering) Address review findings on the review-page image proxy: - IDOR: the proxy fetched any *.githubusercontent.com URL with the App installation token, gated only by route-param repo access, so a user authorized for one repo could read images from another private repo the App can see. Bind the URL to the authorized PR — only proxy URLs that appear in that PR's body. - SVG XSS: served any image/* inline from the API origin, including image/svg+xml which can run script. Restrict to safe raster types and add X-Content-Type-Options: nosniff + a locked-down CSP. - DoS: enforced the size cap only after buffering the full response. Stream and abort once the cap is exceeded. --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| admin.py | ||
| agent_instructions.py | ||
| agent_overrides.py | ||
| agent_usage.py | ||
| analyzer_cron.py | ||
| autofix_state.py | ||
| enabled_repos.py | ||
| eval_jobs.py | ||
| oauth.py | ||
| options.py | ||
| pr_diff.py | ||
| profiles.py | ||
| repo_access.py | ||
| review_api.py | ||
| review_chat_api.py | ||
| review_style_jobs.py | ||
| review_styles.py | ||
| routes.py | ||
| schedules.py | ||
| slack_oauth.py | ||
| team_credentials.py | ||
| team_settings.py | ||
| thread_api.py | ||
| user_credentials.py | ||
| user_mappings.py | ||