Skip to content

fix: bind OOB findings to the probe callback token - #61

Merged
tayfuryldz merged 2 commits into
tayfuryldz:mainfrom
Ymax27:ymax27/fix-oob-callback-token
Oct 2, 2026
Merged

tayfuryldz merged 2 commits into
tayfuryldz:mainfrom
Ymax27:ymax27/fix-oob-callback-token

Conversation

@Ymax27

@Ymax27 Ymax27 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • A blind out-of-band finding is promoted only when returned events have a string token equal to the probe token and a protocol of http or dns.
  • query_events() applies that filter, and analyze_oob_header_probe() derives oob_confirmed from the validated events rather than bool(events).
  • Stored callback evidence keeps token and protocol only, so source addresses and free-form detail are not persisted.
  • Wrong-token, missing-token, malformed, unsupported-protocol, and mixed-event cases are covered. Matching HTTP and DNS callbacks still promote.

Scope

Fixes #36.

This does not weaken the gate to a warning. An unrelated callback cannot satisfy another probe, including when it is returned from /api/events/<expected-token>.

Validation

Commands run on this branch:

PYTHONPATH=src python3 -m pytest -q tests/test_oob.py

Observed result: 5 passed.

ruff and mypy are not installed in this environment, so those gates were not run. The detector/evidence coverage gate was also not run here.

Checklist

  • CLI changes are safe by default and documented.
  • New detection behavior includes tests.
  • False-positive filtering remains conservative by default.
  • Observations/probes are preserved even when findings are filtered.
  • Evidence schema and proof-gate mutation tests pass.
  • No destructive payloads or denial-of-service behavior were added.
  • I reviewed the final diff and can explain the changes I am submitting.
  • Validation results in this PR are from commands actually run on this branch; no results or evidence were fabricated.
  • Any assumptions I could not verify are stated explicitly instead of being presented as facts.

Made with Cursor

@Ymax27
Ymax27 requested a review from tayfuryldz as a code owner October 2, 2026 10:51

@tayfuryldz tayfuryldz left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The functional tests pass, but this branch still fails the repository Ruff gate. tests/test_oob.py has two unused imports: json and BaseHTTPRequestHandler. Please remove those and push the cleanup; I will re-run the full suite after that.

@Ymax27

Ymax27 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

For sure I'm on it

@Ymax27 Ymax27 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unnecessary imports removed

@tayfuryldz tayfuryldz left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, the cleanup fixes the lint issue. I reran the branch against current main: Ruff and mypy are clean, the full test suite passes (122 passed, 3 skipped), and git diff --check is clean.

@tayfuryldz
tayfuryldz enabled auto-merge (squash) October 2, 2026 17:37
Ymax27 and others added 2 commits October 2, 2026 20:37
Promote a blind callback only when the event token and protocol match the probe, and keep the stored callback evidence limited to that correlation.

Co-authored-by: Cursor <cursoragent@cursor.com>
@tayfuryldz
tayfuryldz force-pushed the ymax27/fix-oob-callback-token branch from e923d57 to 01432ce Compare October 2, 2026 17:37
@tayfuryldz
tayfuryldz merged commit 2acaa9b into tayfuryldz:main Oct 2, 2026
8 checks passed
@Ymax27

Ymax27 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

You're welcome.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bind OOB findings to validated matching callback tokens

2 participants