feat: plan 16 P2 batch 1 (SEC-13 SSRF, SEC-27 log-escape, SEC-28 path-traversal)
- SEC-13 (M-09): SSRF allowlist on provider-usage-fetch (always block non-http(s) schemes; enforced mode blocks internal/link-local IPs + non-allowlisted hosts, dev keeps loopback mocks); dashboard refuses non-loopback bind in enforced mode. - SEC-27 (X-02): casan-log strips ESC/CSI + CR/LF (terminal-escape + fake-log-line injection) while keeping tab and visible text. - SEC-28 (X-04): new path-guard.sh — realpath resolve + reject symlink/.. escapes outside the allowed root. Verify: SEC-13 6/0, SEC-27 3/0, SEC-28 4/0, adversarial 44/44, run-casan4 0-FAIL. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
3432ae59e1
commit
8c06a55aed
@@ -1 +1 @@
|
||||
5a25c53485019236dc7383f714812f2ed455c09dde2316e7ce6a9f4a4c58a852
|
||||
636416c4a4e4e7392bcb48b91f7d4b9ea93338c6f3feb469605215917d317e12
|
||||
Reference in New Issue
Block a user