Commit 0cd2b3a8ac

0cd2b3a8acf036c415c8a4dd232aee065d974450

parent: 0c7b382159

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 02:28 UTC

wiki: SSRF control partial while import-issues fetches unpinned

Ref #301

Layout: unified · split

.gitbay/wiki/Architecture/09-Controls.org +1 −1
@@ -75,7 +75,7 @@ chapter names of OWASP ASVS 4.0 where one fits.
75 75
76| Control | Status | Evidence | 76| Control | Status | Evidence |
77|---------------------------------------------+----------+------------------------------------------------------------------| 77|---------------------------------------------+----------+------------------------------------------------------------------|
78| SSRF protection on user-supplied URLs | in place | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=) | 78| SSRF protection on user-supplied URLs | partial | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=); =repo import-issues --api-base= checked once and fetched unpinned (#301) |
79| Webhook payload integrity | in place | HMAC-SHA256 header | 79| Webhook payload integrity | in place | HMAC-SHA256 header |
80| SMTP credentials protected in transit | in place | STARTTLS required for non-local relays, implicit TLS optional (=internal/mail/mail.go=) | 80| SMTP credentials protected in transit | in place | STARTTLS required for non-local relays, implicit TLS optional (=internal/mail/mail.go=) |
81| Upload size limits | in place | per-owner storage quota at push (=internal/sshd/sshd.go=); API body 1 MiB | 81| Upload size limits | in place | per-owner storage quota at push (=internal/sshd/sshd.go=); API body 1 MiB |
.gitbay/wiki/Architecture/10-Known-Gaps.org +1 −1
@@ -13,7 +13,7 @@ what the 2026-09-27 review found; remove a row when its issue closes.
13| #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high | 13| #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high |
14| #260 | CI network | Builds share the runner's source address; no egress policy | medium | 14| #260 | CI network | Builds share the runner's source address; no egress policy | medium |
15| #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium | 15| #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium |
16| #301 | SSRF | =repo import-issues --api-base= fetches without an address check or pin | medium | 16| #301 | SSRF | =repo import-issues --api-base= checks the address once; fetches unpinned | medium |
17 17
18* Not filed 18* Not filed
19 19
.gitbay/wiki/Threat-Model.org +5 −4
@@ -102,10 +102,11 @@ at connect time, and mirror sync and =repo import= resolve and check
102immediately before running git and pin it to the checked addresses 102immediately before running git and pin it to the checked addresses
103(=internal/gitpin=), so a DNS answer that changes after validation 103(=internal/gitpin=), so a DNS answer that changes after validation
104still cannot reach private space. Redirects are never followed. 104still cannot reach private space. Redirects are never followed.
105=repo import= refuses =git://=, which cannot be pinned, and a host 105=repo import= refuses =git://=, which cannot be pinned. Mirror sync
106written as a bare number or in hex/octal (=0x7f.1=, =2130706433=, 106and =repo import= refuse a host written as a bare number or in
107=127.1=) rather than dotted decimal, since that form resolves 107hex/octal (=0x7f.1=, =2130706433=, =127.1=) rather than dotted
108differently across parsers. GitHub-history import (=repo 108decimal, since that form resolves differently across parsers; =repo
109mirror add= refuses it when the mirror is saved. GitHub-history import (=repo
109import-issues --api-base=) is not yet pinned (#301). 110import-issues --api-base=) is not yet pinned (#301).
110 111
111* Rendering pushed markup 112* Rendering pushed markup