mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
A PR head-branch name is attacker-controllable and get_thread_id_from_branch derives a thread_id from its first UUID with no repo binding (TID-COLLIDE-01). The in-memory sandbox cache and the per-thread GitHub-token cache were keyed on thread_id alone, and a cached sandbox was reused after only an echo-ping, so a different repo's webhook could bind to another thread's sandbox or token. Without changing the persistent thread-id scheme: - Persist the bound repo (owner/name) in thread metadata on sandbox creation and refuse to reuse a sandbox whose bound repo does not match the current event (SandboxRepoMismatchError); the in-memory proxy also carries the binding. - Bind the GitHub-token cache entries to their repo and evict on a cross-repo read so a colliding thread_id cannot be served another repo's token. - Thread repo through the reviewer and the webhook token resolvers. |
||
|---|---|---|
| .. | ||
| dashboard | ||
| integrations | ||
| middleware | ||
| skills | ||
| tools | ||
| utils | ||
| analyzer.py | ||
| chat.py | ||
| ci_autofix.py | ||
| ci_monitor.py | ||
| encryption.py | ||
| prompt.py | ||
| review_style_collector.py | ||
| review_style_guidance.py | ||
| reviewer.py | ||
| reviewer_diff.py | ||
| reviewer_eval_store.py | ||
| reviewer_findings.py | ||
| reviewer_groups.py | ||
| reviewer_publish.py | ||
| reviewer_reconcile.py | ||
| scheduler.py | ||
| server.py | ||
| webapp.py | ||