fix(discovery): the docs-fetcher gate checks only the literal host
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 66/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- javascript, shell
- Lĩnh vực
- security
Hướng nghiên cứu
Start with lib/docs-fetcher-gate.mjs (the PreToolUse literal-host check) and lib/fetch-docs.sh (curl with https-only redirects, up to 5). Pick one of the three listed options — address resolution before/after each redirect, post-hoc %{url_effective}/%{remote_ip} inspection, or dropping redirects for the no-allowlist profile — and justify it. Add tests for a redirect-to-private-address refusal and a public-name-resolves-private refusal (local resolver stub or --resolve), keep existing fetcher/gate tests green, and replace the known-limit text in the discovery README (from PR #6481) with the chosen option.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
No related issue: security hardening follow-up to #6348 (part of #6020).
Summary
The PreToolUse gate in lib/docs-fetcher-gate.mjs validates the host written in the command. lib/fetch-docs.sh then runs curl with https-only redirects (up to 5). Two paths bypass the literal-host check:
- A redirect from an allowed or public host to a private-network https address.
- A public DNS name that resolves to a private address.
The discovery docs-fetcher has no host allowlist, so it can be led to a private-network https address. The multi-agent docs fetcher has a first-party allowlist and is not affected the same way. This is documented as a known limit in the discovery README (PR #6481); this issue removes the limit.
Fix
Evaluate and pick one, or a combination:
- Resolve the host and reject private, loopback, link-local and unique-local addresses (IPv4 and IPv6) before the request and again after each redirect. Either pin the checked address with
curl --resolve, or follow redirects manually. - Keep curl's redirect handling but check the outcome:
-w '%{url_effective}'and%{remote_ip}after the transfer, and refuse (and discard the body) when the final address is private. This detects but does not prevent the request, so judge whether that suffices. - Drop redirects for the generic (no allowlist) profile and report the redirect target for the caller to retry explicitly.
Record the chosen option and why in the discovery README, replacing the known-limit text.
Verification
- A test where a redirect to a private address is refused.
- A test where a DNS answer that maps a public name to a private address is refused (a local resolver stub or
--resolveoverride can simulate it). - Existing fetcher and gate tests still pass, and a normal public https fetch with a legitimate redirect still works (if option 3 is not chosen).
Related
- #6020 (umbrella)
- #6348 (shared docs cache, fetcher,
/discovery:read-docs) - PR #6481 (documents the limit in the discovery README)
- Ngôn ngữ chính
- Shell
- Star
- 22
- Fork
- 2
- Merge trung bình
- 5 giờ 4 phút
- Pull request đã merge (30 ngày)
- 825
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6499 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-human needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
melodic-software/claude-code-plugins#6496 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6390 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
melodic-software/claude-code-plugins#6386 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-human needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6363 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của melodic-software/claude-code-plugins
Issue tương tự
-
Lid close does not lock the session on Apple Silicon (lid-close bind skips omarchy-system-lid-close)Đang mở
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 90/100
omacom/omarchy-mac#701 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidateCó thể đã có người làm @armando-navarro đã nhận hôm nay. Đang mởcomp: build/pipeline type: bug version: current (v17+)
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
angular/angularfire#3790 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
ready-for-agent
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
LucasSantana-Dev/Lucky#2698 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
collabnix/awesome-mcp-lists#179 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100