Commit 0cd2b3a8ac
0cd2b3a8acf036c415c8a4dd232aee065d974450
parent: 0c7b382159
Verified · cmc
cmc <hello@cleberg.net> · 2026-09-29 02:28 UTC
wiki: SSRF control partial while import-issues fetches unpinned
Ref #301
Layout: unified · split
.gitbay/wiki/Architecture/09-Controls.org
+1 −1
| @@ -75,7 +75,7 @@ chapter names of OWASP ASVS 4.0 where one fits. |
| 75 | |
75 | |
| 76 | | Control | Status | Evidence | |
76 | | Control | Status | Evidence | |
| 77 | |---------------------------------------------+----------+------------------------------------------------------------------| |
77 | |---------------------------------------------+----------+------------------------------------------------------------------| |
| 78 | | SSRF protection on user-supplied URLs | in place | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=) | |
78 | | SSRF protection on user-supplied URLs | partial | webhooks at save and connect; mirrors at save and sync, =repo import= before its fetch, git pinned to the checked address (=internal/gitpin=); =repo import-issues --api-base= checked once and fetched unpinned (#301) | |
| 79 | | Webhook payload integrity | in place | HMAC-SHA256 header | |
79 | | Webhook payload integrity | in place | HMAC-SHA256 header | |
| 80 | | SMTP credentials protected in transit | in place | STARTTLS required for non-local relays, implicit TLS optional (=internal/mail/mail.go=) | |
80 | | SMTP credentials protected in transit | in place | STARTTLS required for non-local relays, implicit TLS optional (=internal/mail/mail.go=) | |
| 81 | | Upload size limits | in place | per-owner storage quota at push (=internal/sshd/sshd.go=); API body 1 MiB | |
81 | | Upload size limits | in place | per-owner storage quota at push (=internal/sshd/sshd.go=); API body 1 MiB | |
.gitbay/wiki/Architecture/10-Known-Gaps.org
+1 −1
| @@ -13,7 +13,7 @@ what the 2026-09-27 review found; remove a row when its issue closes. |
| 13 | | #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high | |
13 | | #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high | |
| 14 | | #260 | CI network | Builds share the runner's source address; no egress policy | medium | |
14 | | #260 | CI network | Builds share the runner's source address; no egress policy | medium | |
| 15 | | #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium | |
15 | | #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium | |
| 16 | | #301 | SSRF | =repo import-issues --api-base= fetches without an address check or pin | medium | |
16 | | #301 | SSRF | =repo import-issues --api-base= checks the address once; fetches unpinned | medium | |
| 17 | |
17 | |
| 18 | * Not filed |
18 | * Not filed |
| 19 | |
19 | |
.gitbay/wiki/Threat-Model.org
+5 −4
| @@ -102,10 +102,11 @@ at connect time, and mirror sync and =repo import= resolve and check |
| 102 | immediately before running git and pin it to the checked addresses |
102 | immediately before running git and pin it to the checked addresses |
| 103 | (=internal/gitpin=), so a DNS answer that changes after validation |
103 | (=internal/gitpin=), so a DNS answer that changes after validation |
| 104 | still cannot reach private space. Redirects are never followed. |
104 | still cannot reach private space. Redirects are never followed. |
| 105 | =repo import= refuses =git://=, which cannot be pinned, and a host |
105 | =repo import= refuses =git://=, which cannot be pinned. Mirror sync |
| 106 | written as a bare number or in hex/octal (=0x7f.1=, =2130706433=, |
106 | and =repo import= refuse a host written as a bare number or in |
| 107 | =127.1=) rather than dotted decimal, since that form resolves |
107 | hex/octal (=0x7f.1=, =2130706433=, =127.1=) rather than dotted |
| 108 | differently across parsers. GitHub-history import (=repo |
108 | decimal, since that form resolves differently across parsers; =repo |
| |
109 | mirror add= refuses it when the mirror is saved. GitHub-history import (=repo |
| 109 | import-issues --api-base=) is not yet pinned (#301). |
110 | import-issues --api-base=) is not yet pinned (#301). |
| 110 | |
111 | |
| 111 | * Rendering pushed markup |
112 | * Rendering pushed markup |