Skip to content

security: never follow a redirect on a token-bearing request (v0.11.1) - #14

Merged
TadMSTR merged 1 commit into
mainfrom
fix/control-api-no-redirect
Sep 30, 2026
Merged

TadMSTR merged 1 commit into
mainfrom
fix/control-api-no-redirect

Conversation

@TadMSTR

@TadMSTR TadMSTR commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • Never follow a redirect on a token-bearing request. fetch follows redirects by default, and Undici keeps custom headers across the hop. A redirect from the configured TASK_QUEUE_API would therefore have delivered X-Task-Queue-Token (read + operator-write) to whatever origin the Location named. insecureApiBase() only vets the configured base, not where a response points next.
  • send() now passes redirect: 'manual', and any 3xx or opaqueredirect response is refused as a 502 without reading its body. task-queue-mcp never redirects, so there is no behaviour change in normal use.
  • Security audit finding F-01 (Medium). It is the same as CodeRabbit CR-03 on feat: own client token from a file; every queue read through the API (v0.11.0) #13, which was missed before feat: own client token from a file; every queue read through the API (v0.11.0) #13 merged.
  • Released as v0.11.1.

Deliberately not done

  • No redirect-following allowlist. The server never redirects, so any 3xx is a fault to surface, not a hop to vet.
  • The CI gate scripts (src/gates/*.ts) are unchanged. They fetch public raw files with no credential, and already carry a reviewed SECURITY[accepted] for following redirects.

Look hardest at

  • src/control-api.ts send(): the redirect check has to cover both the spec's opaqueredirect (status 0) and Undici's real 3xx.
  • src/tests/control-api.test.ts, "a real redirect to another origin never delivers the token there": two real loopback servers. It fails against v0.11.0.

Test plan

  • npm run build, npm test (204 pass)
  • The two-server test and the redirect: manual test both fail with the fix reverted

🤖 Generated with Claude Code

…uest

Finding: F-01 (audit, Medium) / CR-03 (CodeRabbit, #13) from the
operator-panel-2026-09-p2-queue-read-api audit.

fetch follows redirects by default and Undici keeps X-Task-Queue-Token across
the hop, so a redirect from the configured base would deliver the token to the
Location's origin. send() now passes redirect: 'manual' and refuses any 3xx or
opaque-redirect response as a 502. A two-server loopback test fails on v0.11.0
(the token reaches the redirect target) and passes here. v0.11.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3a7e7d1c-7e61-469f-9230-7dacfe89f79e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@TadMSTR
TadMSTR merged commit a2562b9 into main Sep 30, 2026
3 checks passed
@TadMSTR
TadMSTR deleted the fix/control-api-no-redirect branch September 30, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant