Repository file fetch follows redirects with environment netrc auth enabled
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 58/100
Direzione di ricerca
Start at the /chat/completions/stream handler and trace its call to get_file_content() and get_github_file_content(). Check how Requests handles redirects and environment credentials in this user-supplied repository URL path, then add or run tests covering the reported redirect scenario. Done means the redirect target does not receive server .netrc credentials.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
I found a credential propagation issue in the repository file-content fetch path.
In the current main branch, /chat/completions/stream accepts repo_url, filePath, type, and token. When filePath is present, the handler calls get_file_content(...). For a GitHub Enterprise style URL, get_github_file_content() builds an API URL from the supplied repo_url and calls:
requests.get(api_url, headers=headers)
If token is supplied, the initial request includes Authorization: token .... Requests strips that original header on a cross-host redirect, but because the call uses Requests defaults, trust_env remains enabled. Requests can then refill Authorization from the server process .netrc for the redirect target.
I reproduced this against commit 16f35a0fc0284e99b7963bbf4e8585e9957e2fe1 with the documented Poetry install. The resolved versions included:
requests==2.32.5
aiohttp==3.13.1
tqdm==4.67.1
The reproduction used only loopback servers and fake canary credentials. A request to /chat/completions/stream with a controlled GitHub Enterprise style repo_url and filePath=README.md caused the file-content fetch to follow a redirect. The controlled redirect target received:
Authorization: Basic TElCMkFQUF9FTkRQT0lOVF9SRUZJTExfTE9HSU46TElCMkFQUF9FTkRQT0lOVF9SRUZJTExfUEFTU1dPUkQ=
Decoded:
LIB2APP_ENDPOINT_REFILL_LOGIN:LIB2APP_ENDPOINT_REFILL_PASSWORD
The original Authorization: token ... header was not leaked. This issue is specifically that server-side .netrc credentials can be attached to an attacker-influenced redirect target during repository file fetching.
Impact depends on the server process having a matching .netrc entry and on a repository/file request that reaches this redirect path. In that configuration, an untrusted repository API response can make the DeepWiki backend send environment credentials to the redirect target.
Suggested mitigations:
- Use a
requests.Session()withtrust_env = Falsefor repository and file-content fetches that use user-supplied repository URLs. - Consider disallowing cross-host redirects, or at least restricting redirects to the expected repository API host.
- Avoid applying server environment credentials to repository URLs supplied by users.
- Lingua principale
- Python
- Stelle
- 18.1k
- Fork
- 2k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AsyncFuncAI/deepwiki-open
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
AsyncFuncAI/deepwiki-open#608 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#602 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
AsyncFuncAI/deepwiki-open#589 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#539 · 1 commento ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
AsyncFuncAI/deepwiki-open#610 ·
Tutte le issue di AsyncFuncAI/deepwiki-open
Issue simili
-
changelog investigate
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
ramnes/notion-sdk-py#409 ·
-
good first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
lindicaphxag-tech/kaggle#28 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
BSData/horus-heresy-3rd-edition#3211 ·
I maintainer di solito rispondono entro 1 giorno
-
bug needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
bug tests
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno