Repository navigation
Harden token/error handling, enforce HTTPS-or-loopback, and pin supply-chain versions - #2
Merged
Merged
Conversation
…y-chain versions across Node/Java/Go SDKs Second round of codex-audited security fixes on top of the redirect/token-validation work already in this PR: - Tighten Java token/header validation to a printable-ASCII whitelist and enforce it inside QdmpTransport too, closing a direct-construction bypass of QdmpContext - Reject non-numeric, negative, and already-expired expiresAt values on all three auth exchange paths (cached app token and one-shot code2Session/refreshToken) in Go/Java, and validate refreshToken/openId are non-empty across all three languages - Replace Java's code2Session/refreshToken generated-DTO return types (which leaked tokens via auto-generated toString()) with hand-written Code2SessionResult/RefreshTokenResult, matching Go's existing types - Require HTTPS by default in all three SDKs, using a real IP-literal loopback check (the previous string-prefix check could be bypassed by a hostname like "127.attacker.com") - Sanitize server-controlled message/code/requestId fields (control-character stripping + length caps) before they reach any error string, and cap response body reads at 10MB - Prevent accidental debug-logging of tokens: Go's Code2SessionResult/RefreshTokenResult now implement fmt.Stringer/GoStringer/slog.LogValuer, Node's results carry a redacted util.inspect renderer, Java's toString() also escapes control characters in openId - Fix a Node ordering bug where a failed TokenStore write could still leave a token locally cached as if persisted - Pin/verify supply-chain inputs: SHA-256-verify the downloaded openapi-generator-cli jar, pin Go's oapi-codegen to v2.8.0 via `go run`, add Gradle wrapper's distributionSha256Sum, pin staticcheck's version ## Test plan - Node: 91/91 tests, typecheck, lint clean - Java: full suite + checkstyle/spotless clean - Go: 81/81 tests (-race), gofmt/vet clean
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Second round of codex-audited security fixes on top of the redirect/token-validation work from #1 (merged): Java token/header validation tightened to a printable-ASCII whitelist with a QdmpTransport-level enforcement to close a direct-construction bypass; expiresAt is now validated as non-negative and not-already-expired on every auth exchange path (cached and one-shot) in Go/Java, with refreshToken/openId non-empty checks across all three languages; Java's code2Session/refreshToken now return hand-written Code2SessionResult/RefreshTokenResult instead of generated DTOs whose auto-generated toString() leaked tokens; all three SDKs require HTTPS by default using a real IP-literal loopback check (the previous string-prefix check was bypassable via a hostname like "127.attacker.com"); server-controlled message/code/requestId fields are sanitized before reaching any error string, and response bodies are capped at 10MB; accidental debug-logging of tokens is now blocked across fmt/GoStringer/slog (Go), util.inspect (Node), and toString (Java); a Node ordering bug that could leave a failed TokenStore write locally cached as if persisted is fixed; and supply-chain inputs are pinned/verified (openapi-generator-cli jar SHA-256, Go's oapi-codegen pinned to v2.8.0, Gradle wrapper checksum, staticcheck version).
Test plan