Use type system to prevent request validation bypasses
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 30/100
- Tipo di issue
- Refactoring
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- rust
- Ambito
- backend-api-design, security
Direzione di ricerca
Inizia individuando il punto di ingresso per la gestione delle richieste proxy e la RuleEngine, quindi segui il modo in cui le richieste vengono convalidate, trasformate e inviate all’upstream. L’issue non indica file o test; il lavoro è completato quando l’inoltro all’upstream accetta solo un tipo che può essere creato dopo la convalida, con le verifiche di bypass dell’Host-header e quelle correlate coperte.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
We should refactor the proxy request handling to use the type system to ensure all requests passed to upstream servers have been validated by the RuleEngine, making it impossible at compile time to accidentally bypass security checks.
Background
While fixing the Host header bypass vulnerability (#57), we added runtime validation to ensure the Host header matches the URI. However, this and similar security checks could be better enforced through the type system.
Proposed Solution
Introduce type-safe request handling that guarantees validation:
// Example approach
struct ValidatedRequest {
// Can only be constructed after passing RuleEngine validation
inner: Request<BoxBody<Bytes, HyperError>>,
}
impl ValidatedRequest {
// Private constructor - only RuleEngine can create these
fn new(request: Request, validation_result: RuleEvaluation) -> Result<Self> {
// Ensure all headers match validated URL
// Apply any security transformations
}
}
// Upstream client only accepts ValidatedRequest
fn send_to_upstream(request: ValidatedRequest) -> Result<Response> {
// Impossible to send unvalidated requests
}
Benefits
- Compile-time safety - Makes it impossible to accidentally forward unvalidated or modified requests
- Clear security boundaries - Type system enforces that all upstream requests go through validation
- Prevents regression - New code can't accidentally bypass security checks
- Self-documenting - Types make security requirements explicit
- Lingua principale
- Rust
- Stelle
- 962
- Fork
- 28
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di coder/httpjail
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
Provide Docker Container Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Request mutation? Aperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
Tutte le issue di coder/httpjail
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
web-infra-dev/rspack#15847 ·