🛡️ Sentinel: [HIGH] Fix Server-Side Request Forgery in webhooks
Adds validation to webhook URLs before attempting to deliver them to prevent SSRF attacks targeting private IP ranges, local host, and cloud metadata endpoints. Validates URL schema, hostname, and applies `is_private_ip()`. Also resolved ruff linting errors. Tests have been expanded to ensure validation covers all cases. Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -924,3 +924,29 @@ class TestURLUploadCoverageGaps:
|
||||
|
||||
# Should not raise any exception and should ignore missing Location header
|
||||
await verify_redirect(resp)
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_verify_redirect_coverage():
|
||||
from app.api.url_upload import verify_redirect
|
||||
|
||||
response = MagicMock(spec=httpx.Response)
|
||||
response.status_code = 301
|
||||
response.headers = httpx.Headers({"Location": "ftp://example.com"})
|
||||
response.url = httpx.URL("http://test.com")
|
||||
response.request = MagicMock(spec=httpx.Request)
|
||||
|
||||
with pytest.raises(httpx.RequestError):
|
||||
await verify_redirect(response)
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_verify_redirect_coverage2():
|
||||
from app.api.url_upload import verify_redirect
|
||||
|
||||
response = MagicMock(spec=httpx.Response)
|
||||
response.status_code = 301
|
||||
response.headers = httpx.Headers({"Location": "http://example.com"})
|
||||
response.url = httpx.URL("http://test.com")
|
||||
response.request = MagicMock(spec=httpx.Request)
|
||||
|
||||
# Should be fine
|
||||
await verify_redirect(response)
|
||||
|
||||
Reference in New Issue
Block a user