 thanhnvandClaude Opus 4.8
|
8c06a55aed
|
feat: plan 16 P2 batch 1 (SEC-13 SSRF, SEC-27 log-escape, SEC-28 path-traversal)
- SEC-13 (M-09): SSRF allowlist on provider-usage-fetch (always block non-http(s)
schemes; enforced mode blocks internal/link-local IPs + non-allowlisted hosts,
dev keeps loopback mocks); dashboard refuses non-loopback bind in enforced mode.
- SEC-27 (X-02): casan-log strips ESC/CSI + CR/LF (terminal-escape + fake-log-line
injection) while keeping tab and visible text.
- SEC-28 (X-04): new path-guard.sh — realpath resolve + reject symlink/.. escapes
outside the allowed root.
Verify: SEC-13 6/0, SEC-27 3/0, SEC-28 4/0, adversarial 44/44, run-casan4 0-FAIL.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
2026-07-06 22:39:18 +09:00 |
|