mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 17:23:15 +00:00
* fix(webhooks): fall back to vision model for Slack/Linear image threads Re-land upstream #1626 onto the modular webhook structure. When a Slack mention or Linear issue carries images but the resolved model is text-only, fall back to a vision-capable model instead of dropping the images. Re-points default_vision_model_pair at the fork's image-capable models (Opus 4.8 default, else any supports_images model) rather than upstream's openai:/anthropic: provider filter. Refs #80, upstream #1626 * fix(slack): persist trace_message_ts so web-handoff updates the trace reply Re-land upstream #1630 onto the modular structure. The first-mention store_slack_run_mapping call did not pass trace_message_ts, so it was never persisted (nothing to preserve from on first mention) and _notify_slack_web_handoff always skipped the trace-reply update on web handoff. Pass it through and cover it with a test. Refs #80, upstream #1630 * feat(slack): include channel context in Slack prompts Re-land upstream #1633 onto the modular structure. Fetch cached Slack channel metadata once per event (_get_slack_channel_context) and thread it through the docs-plz gate, repo resolution, and process_slack_mention so prompts carry the channel name and a clearly-marked untrusted channel description. Avoids duplicate conversations.info calls. Refs #80, upstream #1633 * feat(tools): add slack_start_new_thread breakout tool Re-land upstream #1638 onto the modular structure. Adds the slack_start_new_thread tool (posts a top-level Slack message and dispatches a fresh agent run for a broken-out task via the durable dispatch_agent_run contract), wires it into the agent tool list and tools/__init__, adds prompt guidance, and excludes it from plan mode so it can't bypass the approval flow. Tool imports only live modules. Refs #80, upstream #1638 * feat(plan): notify Slack on plan approval Re-land upstream #1632 onto the modular structure. When a plan is approved via the dashboard approve endpoint, post a thread reply to the originating Slack thread noting the comment count and approver, after the follow-up run is dispatched. Slack post failures never break approval. Adapted to the fork's approve_plan (no plan_markdown read). Refs #80, upstream #1632 * feat(plan): publish plans from sandbox files Re-land upstream #1635 onto the modular structure, completing the partially-ported change so dev is internally consistent. save_plan now takes a plan_file_path, reads the agent-authored Markdown file from /workspace/plans/ (validating extension/location/UTF-8/size) and publishes it, instead of taking a plan_markdown string. Removes write_file/edit_file from PLAN_MODE_EXCLUDED_TOOLS so the agent can author the plan file, updates enter_plan_mode/reject_plan guidance and the e2e fake LLM. Skips the #1610-only update_plan hunk (not on dev). Refs #80, upstream #1635 * fix(security): SSRF-harden server-side image fetch + stop logging raw image URLs INJ-01 (high): fetch_image_block used follow_redirects=True with no per-hop revalidation and discarded the resolved-IP pin, so an attacker-authored Slack/ Linear image URL could 302-redirect the fetch to an internal host / cloud metadata endpoint (blind SSRF), and DNS-rebinding could bypass the one-shot is_url_safe check. Route image fetches through the same per-hop resolve+pin+ revalidate loop the http_request tool uses, lifted into url_safety as the shared request_with_safe_redirects. Also strip the per-host Slack/Linear bearer token on redirect so it can't be replayed to a redirect target. SC-1 (low): linear.py logged full image URLs (which can carry signed tokens) at DEBUG; multimodal logged them at INFO on every fetch. Log host-only. Sink lived in multimodal.py (unchanged by the feature work) but PR #128 widened its reach by no longer dropping images for text-only models. Fixing on the base branch so #130/#129 inherit it on rebase. Adds fetch_image_block SSRF regression tests (redirect-to-internal blocked; auth stripped on redirect).
110 lines
3.2 KiB
Python
110 lines
3.2 KiB
Python
from typing import Any
|
|
|
|
import httpx
|
|
|
|
from ..utils.url_safety import pinned_url as _pinned_url # noqa: F401 (kept for tests)
|
|
from ..utils.url_safety import request_with_safe_redirects
|
|
from ..utils.url_safety import resolve_and_validate as _resolve_and_validate # noqa: F401
|
|
|
|
|
|
def _blocked_response(url: str, reason: str) -> dict[str, Any]:
|
|
return {
|
|
"success": False,
|
|
"status_code": 0,
|
|
"headers": {},
|
|
"content": f"Request blocked: {reason}",
|
|
"url": url,
|
|
}
|
|
|
|
|
|
async def _request_with_safe_redirects(
|
|
client: httpx.AsyncClient,
|
|
method: str,
|
|
url: str,
|
|
**kwargs: Any,
|
|
) -> tuple[httpx.Response | None, dict[str, Any] | None]:
|
|
"""Thin wrapper over the shared SSRF-safe redirect loop that shapes a blocked
|
|
hop into the tool's error-response dict."""
|
|
response, blocked = await request_with_safe_redirects(client, method, url, **kwargs)
|
|
if blocked is not None:
|
|
blocked_url, reason = blocked
|
|
return None, _blocked_response(blocked_url, reason)
|
|
return response, None
|
|
|
|
|
|
async def http_request(
|
|
url: str,
|
|
method: str = "GET",
|
|
headers: dict[str, str] | None = None,
|
|
data: str | dict | None = None,
|
|
params: dict[str, str] | None = None,
|
|
timeout: int = 30,
|
|
) -> dict[str, Any]:
|
|
"""Make HTTP requests to APIs and web services.
|
|
|
|
Do not use this tool for GitHub API calls. Use `GH_TOKEN=dummy gh` in the
|
|
sandbox so GitHub authentication is handled by the sandbox proxy.
|
|
|
|
Args:
|
|
url: Target URL
|
|
method: HTTP method (GET, POST, PUT, DELETE, etc.)
|
|
headers: HTTP headers to include
|
|
data: Request body data (string or dict)
|
|
params: URL query parameters
|
|
timeout: Request timeout in seconds
|
|
|
|
Returns:
|
|
Dictionary with response data including status, headers, and content
|
|
"""
|
|
try:
|
|
kwargs: dict[str, Any] = {}
|
|
|
|
if headers:
|
|
kwargs["headers"] = headers
|
|
if params:
|
|
kwargs["params"] = params
|
|
if data:
|
|
if isinstance(data, dict):
|
|
kwargs["json"] = data
|
|
else:
|
|
kwargs["content"] = data
|
|
|
|
async with httpx.AsyncClient(timeout=timeout) as client:
|
|
response, blocked = await _request_with_safe_redirects(
|
|
client,
|
|
method,
|
|
url,
|
|
**kwargs,
|
|
)
|
|
if blocked:
|
|
return blocked
|
|
|
|
try:
|
|
content = response.json()
|
|
except ValueError:
|
|
content = response.text
|
|
|
|
return {
|
|
"success": response.status_code < 400,
|
|
"status_code": response.status_code,
|
|
"headers": dict(response.headers),
|
|
"content": content,
|
|
"url": str(response.url),
|
|
}
|
|
|
|
except httpx.TimeoutException:
|
|
return {
|
|
"success": False,
|
|
"status_code": 0,
|
|
"headers": {},
|
|
"content": f"Request timed out after {timeout} seconds",
|
|
"url": url,
|
|
}
|
|
except httpx.HTTPError as e:
|
|
return {
|
|
"success": False,
|
|
"status_code": 0,
|
|
"headers": {},
|
|
"content": f"Request error: {e!s}",
|
|
"url": url,
|
|
}
|