mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 06:53:14 +00:00
* fix: harden http_request SSRF guard against DNS rebinding [closes AB-2321] Pin DNS resolution per request hop so urllib3's connection-time lookup cannot rebind to a private IP after _is_url_safe validated a public one. Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com> * fix: scope DNS pin to urllib3 with reference-counted install Address review feedback: the previous version permanently overwrote the process-global socket.getaddrinfo on first use. Now the patch targets urllib3.util.connection.create_connection (much narrower blast radius), and is installed/uninstalled via reference count so no global mutation persists once no http_request calls are in flight. Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com> * fix: forward timeout and socket_options through pinned create_connection urllib3 calls create_connection with timeout positional and socket_options as a keyword. The previous wrapper only read kwargs, silently dropping the caller's connect timeout (so a slow validated IP could hang) and TCP options like TCP_NODELAY. Accept both positionally and forward them to the underlying socket. --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com> Co-authored-by: Johannes du Plessis <johannes@langchain.dev> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| add_finding.py | ||
| fetch_url.py | ||
| http_request.py | ||
| linear_comment.py | ||
| linear_create_issue.py | ||
| linear_delete_issue.py | ||
| linear_get_issue.py | ||
| linear_get_issue_comments.py | ||
| linear_list_teams.py | ||
| linear_update_issue.py | ||
| list_findings.py | ||
| publish_review.py | ||
| request_pr_review.py | ||
| slack_read_thread_messages.py | ||
| slack_thread_reply.py | ||
| update_finding.py | ||
| web_search.py | ||