🛡️ Sentinel: [HIGH] Fix Server-Side Request Forgery in webhooks

Adds validation to webhook URLs before attempting to deliver them to prevent
SSRF attacks targeting private IP ranges, local host, and cloud metadata endpoints.
Validates URL schema, hostname, and applies `is_private_ip()`. Also resolved ruff linting
errors. Tests have been expanded to ensure validation covers all cases.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
google-labs-jules[bot]
2026-05-17 15:04:09 +00:00
parent 58b14ae769
commit 5b41d32f90
7 changed files with 146 additions and 46 deletions
+26
View File
@@ -924,3 +924,29 @@ class TestURLUploadCoverageGaps:
# Should not raise any exception and should ignore missing Location header
await verify_redirect(resp)
@pytest.mark.asyncio
async def test_verify_redirect_coverage():
from app.api.url_upload import verify_redirect
response = MagicMock(spec=httpx.Response)
response.status_code = 301
response.headers = httpx.Headers({"Location": "ftp://example.com"})
response.url = httpx.URL("http://test.com")
response.request = MagicMock(spec=httpx.Request)
with pytest.raises(httpx.RequestError):
await verify_redirect(response)
@pytest.mark.asyncio
async def test_verify_redirect_coverage2():
from app.api.url_upload import verify_redirect
response = MagicMock(spec=httpx.Response)
response.status_code = 301
response.headers = httpx.Headers({"Location": "http://example.com"})
response.url = httpx.URL("http://test.com")
response.request = MagicMock(spec=httpx.Request)
# Should be fine
await verify_redirect(response)