Repository navigation
docs(security): align security docs with recent hardening fixes - #33
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 24, 2026
Merged
Conversation
Reflect the controls added in #28 (review/w1a), #31 (vulnerable transitive deps), #32 (CodeQL HIGH/MEDIUM closure) and f3eb8ae (sandbox entrypoint hardening) in the security-facing docs. No code changes. docs/security.md - New 'Admin-plane hardening' table under Layer 7 covering: constant-time admin-token compare, #[serde(deny_unknown_fields)] on SpawnRequest/HandoffMeta, ROUTER_ADMIN_ALLOW_IPS, ADMIN_ALLOWED_ORIGINS, canonical 'Authorization: Bearer' header, handoff middleware no-localhost-bypass, per-request size caps, trace-id sanitization, controller-set-only AZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINT test overrides. Each row carries file:line citations into inference-router/. - New 'Operator CLI & Plugin Hardening' section covering the CodeQL fixes: redactSecrets() (Bearer/JWT/PEM/azcp_*/keyword secrets, ReDoS-bounded), sanitizeForLog() (CRLF/tab strip, CodeQL-recognized split-replace pattern), escapeHtml() on the OAuth callback page, mkdtempSync() per-request tmpdir, openSync+fstatSync+readSync TOCTOU-safe reads, execFileSync('find', [...]) no-shell exec. - New 'Sandbox entrypoint hardening' subsection: EPERM-tolerant chmod/fchmod, AGT_POLICY_DIR profile-leak fix, plugin/SDK/node_modules re-chowned to root RO, regression test asserts every hardening invariant. - New 'Supply-chain & dependency hygiene' subsection: cargo audit CI job (closed RUSTSEC-2026-0098/-0099/-0104 via rustls-webpki bump), npm overrides (uuid/xml2js/lodash), vendored Python wheel + Go toolchain bumps, AgentMesh Cargo.lock bumps, fuzz/proptest targets. docs/security-validation.md - New 'Cross-cutting Hardening' section maps each new control to its automated test (cli/src/redact.test.ts, sandbox-hardening.test.ts, inference-router unit tests, cargo audit, npm audit, cargo fuzz) and provides a one-block reproduction recipe. README.md - Updated 'Admin token' row in Security Model: canonical 'Authorization: Bearer', x-azureclaw-admin deprecation, constant-time compare, ROUTER_ADMIN_ALLOW_IPS / ADMIN_ALLOWED_ORIGINS allowlists. docs/threat-model.md and CHANGELOG.md were already accurate and unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
docs/security-hardening-update
branch
April 24, 2026 10:11
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Reflect the controls added in #28 (review/w1a), #31 (vulnerable transitive deps), #32 (CodeQL HIGH/MEDIUM closure) and 22197bc (sandbox entrypoint hardening) in the security-facing docs. No code changes. docs/security.md - New 'Admin-plane hardening' table under Layer 7 covering: constant-time admin-token compare, #[serde(deny_unknown_fields)] on SpawnRequest/HandoffMeta, ROUTER_ADMIN_ALLOW_IPS, ADMIN_ALLOWED_ORIGINS, canonical 'Authorization: Bearer' header, handoff middleware no-localhost-bypass, per-request size caps, trace-id sanitization, controller-set-only AZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINT test overrides. Each row carries file:line citations into inference-router/. - New 'Operator CLI & Plugin Hardening' section covering the CodeQL fixes: redactSecrets() (Bearer/JWT/PEM/azcp_*/keyword secrets, ReDoS-bounded), sanitizeForLog() (CRLF/tab strip, CodeQL-recognized split-replace pattern), escapeHtml() on the OAuth callback page, mkdtempSync() per-request tmpdir, openSync+fstatSync+readSync TOCTOU-safe reads, execFileSync('find', [...]) no-shell exec. - New 'Sandbox entrypoint hardening' subsection: EPERM-tolerant chmod/fchmod, AGT_POLICY_DIR profile-leak fix, plugin/SDK/node_modules re-chowned to root RO, regression test asserts every hardening invariant. - New 'Supply-chain & dependency hygiene' subsection: cargo audit CI job (closed RUSTSEC-2026-0098/-0099/-0104 via rustls-webpki bump), npm overrides (uuid/xml2js/lodash), vendored Python wheel + Go toolchain bumps, AgentMesh Cargo.lock bumps, fuzz/proptest targets. docs/security-validation.md - New 'Cross-cutting Hardening' section maps each new control to its automated test (cli/src/redact.test.ts, sandbox-hardening.test.ts, inference-router unit tests, cargo audit, npm audit, cargo fuzz) and provides a one-block reproduction recipe. README.md - Updated 'Admin token' row in Security Model: canonical 'Authorization: Bearer', x-azureclaw-admin deprecation, constant-time compare, ROUTER_ADMIN_ALLOW_IPS / ADMIN_ALLOWED_ORIGINS allowlists. docs/threat-model.md and CHANGELOG.md were already accurate and unchanged. Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reflect the controls landed in #28, #31, #32 and
f3eb8aein the security-facing docs. Docs-only — no code changes.What changed
docs/security.md#[serde(deny_unknown_fields)]onSpawnRequest/HandoffMeta,ROUTER_ADMIN_ALLOW_IPS,ADMIN_ALLOWED_ORIGINS, canonicalAuthorization: Bearer, handoff middleware no-localhost-bypass, per-request size caps, trace-id sanitization, controller-set-onlyAZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINTtest overrides — each row carries file:line citations.redactSecrets(),sanitizeForLog(),escapeHtml(),mkdtempSyncper-request tmpdir,openSync+fstatSync+readSyncTOCTOU-safe reads,execFileSync('find', […])no-shell exec.f3eb8ae): EPERM-tolerant chmod,AGT_POLICY_DIRprofile-leak fix, plugin/SDK/node_modules root-owned RO + the regression test.cargo auditCI job, npm overrides foruuid/xml2js/lodash, vendored Python wheel + Go toolchain bumps, AgentMeshCargo.lockbumps, fuzz/proptest targets.docs/security-validation.mdcd cli && npm test,cargo test --all,npm audit,cargo audit).README.mdAuthorization: Bearerheader,x-azureclaw-admindeprecation note, constant-time compare, optionalROUTER_ADMIN_ALLOW_IPS/ADMIN_ALLOWED_ORIGINSallowlists.What was not changed
docs/threat-model.md— already covers every new admin-plane control with route-level granularity.CHANGELOG.md—### Securityblock under[Unreleased]already enumerates these items.Verification
Docs-only PR. No build/test impact.