Commit 0cd2b3a8ac
0cd2b3a8acf036c415c8a4dd232aee065d974450
parent: 0c7b382159
Verified · cmc
cmc <hello@cleberg.net> · 2026-09-29 02:28 UTC
wiki: SSRF control partial while import-issues fetches unpinned
Ref #301
Layout: unified · split
.gitbay/wiki/Architecture/09-Controls.org
+1 −1
| @@ -75,7 +75,7 @@ chapter names of OWASP ASVS 4.0 where one fits. |
| 75 | 75 | |
| 76 | 76 | | Control | Status | Evidence | |
| 77 | 77 | |---------------------------------------------+----------+------------------------------------------------------------------| |
| 78 | | | SSRF protection on user-supplied URLs | in place | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=) | |
| 78 | | SSRF protection on user-supplied URLs | partial | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=); =repo import-issues --api-base= checked once and fetched unpinned (#301) | |
| 79 | 79 | | Webhook payload integrity | in place | HMAC-SHA256 header | |
| 80 | 80 | | SMTP credentials protected in transit | in place | STARTTLS required for non-local relays, implicit TLS optional (=internal/mail/mail.go=) | |
| 81 | 81 | | Upload size limits | in place | per-owner storage quota at push (=internal/sshd/sshd.go=); API body 1 MiB | |
.gitbay/wiki/Architecture/10-Known-Gaps.org
+1 −1
| @@ -13,7 +13,7 @@ what the 2026-09-27 review found; remove a row when its issue closes. |
| 13 | 13 | | #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high | |
| 14 | 14 | | #260 | CI network | Builds share the runner's source address; no egress policy | medium | |
| 15 | 15 | | #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium | |
| 16 | | | #301 | SSRF | =repo import-issues --api-base= fetches without an address check or pin | medium | |
| 16 | | #301 | SSRF | =repo import-issues --api-base= checks the address once; fetches unpinned | medium | |
| 17 | 17 | |
| 18 | 18 | * Not filed |
| 19 | 19 | |
.gitbay/wiki/Threat-Model.org
+5 −4
| @@ -102,10 +102,11 @@ at connect time, and mirror sync and =repo import= resolve and check |
| 102 | 102 | immediately before running git and pin it to the checked addresses |
| 103 | 103 | (=internal/gitpin=), so a DNS answer that changes after validation |
| 104 | 104 | still cannot reach private space. Redirects are never followed. |
| 105 | | =repo import= refuses =git://=, which cannot be pinned, and a host |
| 106 | | written as a bare number or in hex/octal (=0x7f.1=, =2130706433=, |
| 107 | | =127.1=) rather than dotted decimal, since that form resolves |
| 108 | | differently across parsers. GitHub-history import (=repo |
| 105 | =repo import= refuses =git://=, which cannot be pinned. Mirror sync |
| 106 | and =repo import= refuse a host written as a bare number or in |
| 107 | hex/octal (=0x7f.1=, =2130706433=, =127.1=) rather than dotted |
| 108 | decimal, since that form resolves differently across parsers; =repo |
| 109 | mirror add= refuses it when the mirror is saved. GitHub-history import (=repo |
| 109 | 110 | import-issues --api-base=) is not yet pinned (#301). |
| 110 | 111 | |
| 111 | 112 | * Rendering pushed markup |