Skip to content

docs(security): align security docs with recent hardening fixes - #33

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
docs/security-hardening-update
Apr 24, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
docs/security-hardening-update

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Reflect the controls landed in #28, #31, #32 and f3eb8ae in the security-facing docs. Docs-only — no code changes.

What changed

docs/security.md

  • New Admin-plane hardening table under Layer 7: constant-time admin-token compare, #[serde(deny_unknown_fields)] on SpawnRequest/HandoffMeta, ROUTER_ADMIN_ALLOW_IPS, ADMIN_ALLOWED_ORIGINS, canonical Authorization: Bearer, handoff middleware no-localhost-bypass, per-request size caps, trace-id sanitization, controller-set-only AZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINT test overrides — each row carries file:line citations.
  • New Operator CLI & Plugin Hardening section covering the CodeQL fixes from fix(security): resolve CodeQL HIGH/MEDIUM code-scanning findings #32: redactSecrets(), sanitizeForLog(), escapeHtml(), mkdtempSync per-request tmpdir, openSync+fstatSync+readSync TOCTOU-safe reads, execFileSync('find', […]) no-shell exec.
  • New Sandbox entrypoint hardening subsection (from f3eb8ae): EPERM-tolerant chmod, AGT_POLICY_DIR profile-leak fix, plugin/SDK/node_modules root-owned RO + the regression test.
  • New Supply-chain & dependency hygiene subsection: cargo audit CI job, npm overrides for uuid/xml2js/lodash, vendored Python wheel + Go toolchain bumps, AgentMesh Cargo.lock bumps, fuzz/proptest targets.

docs/security-validation.md

  • New Cross-cutting Hardening section maps each new control to its automated test (no live cluster needed) and provides a one-block reproduction recipe (cd cli && npm test, cargo test --all, npm audit, cargo audit).

README.md

  • Updated the Admin token row in the Security Model table: canonical Authorization: Bearer header, x-azureclaw-admin deprecation note, constant-time compare, optional ROUTER_ADMIN_ALLOW_IPS / ADMIN_ALLOWED_ORIGINS allowlists.

What was not changed

  • docs/threat-model.md — already covers every new admin-plane control with route-level granularity.
  • CHANGELOG.md — ### Security block under [Unreleased] already enumerates these items.

Verification

Docs-only PR. No build/test impact.

Reflect the controls added in #28 (review/w1a), #31 (vulnerable transitive
deps), #32 (CodeQL HIGH/MEDIUM closure) and f3eb8ae (sandbox entrypoint
hardening) in the security-facing docs. No code changes.

docs/security.md
- New 'Admin-plane hardening' table under Layer 7 covering:
  constant-time admin-token compare, #[serde(deny_unknown_fields)] on
  SpawnRequest/HandoffMeta, ROUTER_ADMIN_ALLOW_IPS, ADMIN_ALLOWED_ORIGINS,
  canonical 'Authorization: Bearer' header, handoff middleware
  no-localhost-bypass, per-request size caps, trace-id sanitization,
  controller-set-only AZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINT test overrides.
  Each row carries file:line citations into inference-router/.
- New 'Operator CLI & Plugin Hardening' section covering the CodeQL fixes:
  redactSecrets() (Bearer/JWT/PEM/azcp_*/keyword secrets, ReDoS-bounded),
  sanitizeForLog() (CRLF/tab strip, CodeQL-recognized split-replace
  pattern), escapeHtml() on the OAuth callback page, mkdtempSync()
  per-request tmpdir, openSync+fstatSync+readSync TOCTOU-safe reads,
  execFileSync('find', [...]) no-shell exec.
- New 'Sandbox entrypoint hardening' subsection: EPERM-tolerant
  chmod/fchmod, AGT_POLICY_DIR profile-leak fix, plugin/SDK/node_modules
  re-chowned to root RO, regression test asserts every hardening
  invariant.
- New 'Supply-chain & dependency hygiene' subsection: cargo audit CI
  job (closed RUSTSEC-2026-0098/-0099/-0104 via rustls-webpki bump),
  npm overrides (uuid/xml2js/lodash), vendored Python wheel + Go
  toolchain bumps, AgentMesh Cargo.lock bumps, fuzz/proptest targets.

docs/security-validation.md
- New 'Cross-cutting Hardening' section maps each new control to its
  automated test (cli/src/redact.test.ts, sandbox-hardening.test.ts,
  inference-router unit tests, cargo audit, npm audit, cargo fuzz)
  and provides a one-block reproduction recipe.

README.md
- Updated 'Admin token' row in Security Model: canonical
  'Authorization: Bearer', x-azureclaw-admin deprecation, constant-time
  compare, ROUTER_ADMIN_ALLOW_IPS / ADMIN_ALLOWED_ORIGINS allowlists.

docs/threat-model.md and CHANGELOG.md were already accurate and unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit d4165da into main Apr 24, 2026
14 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the docs/security-hardening-update branch April 24, 2026 10:11
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Reflect the controls added in #28 (review/w1a), #31 (vulnerable transitive
deps), #32 (CodeQL HIGH/MEDIUM closure) and 22197bc (sandbox entrypoint
hardening) in the security-facing docs. No code changes.

docs/security.md
- New 'Admin-plane hardening' table under Layer 7 covering:
  constant-time admin-token compare, #[serde(deny_unknown_fields)] on
  SpawnRequest/HandoffMeta, ROUTER_ADMIN_ALLOW_IPS, ADMIN_ALLOWED_ORIGINS,
  canonical 'Authorization: Bearer' header, handoff middleware
  no-localhost-bypass, per-request size caps, trace-id sanitization,
  controller-set-only AZURE_IMDS_ENDPOINT/AZURE_AD_ENDPOINT test overrides.
  Each row carries file:line citations into inference-router/.
- New 'Operator CLI & Plugin Hardening' section covering the CodeQL fixes:
  redactSecrets() (Bearer/JWT/PEM/azcp_*/keyword secrets, ReDoS-bounded),
  sanitizeForLog() (CRLF/tab strip, CodeQL-recognized split-replace
  pattern), escapeHtml() on the OAuth callback page, mkdtempSync()
  per-request tmpdir, openSync+fstatSync+readSync TOCTOU-safe reads,
  execFileSync('find', [...]) no-shell exec.
- New 'Sandbox entrypoint hardening' subsection: EPERM-tolerant
  chmod/fchmod, AGT_POLICY_DIR profile-leak fix, plugin/SDK/node_modules
  re-chowned to root RO, regression test asserts every hardening
  invariant.
- New 'Supply-chain & dependency hygiene' subsection: cargo audit CI
  job (closed RUSTSEC-2026-0098/-0099/-0104 via rustls-webpki bump),
  npm overrides (uuid/xml2js/lodash), vendored Python wheel + Go
  toolchain bumps, AgentMesh Cargo.lock bumps, fuzz/proptest targets.

docs/security-validation.md
- New 'Cross-cutting Hardening' section maps each new control to its
  automated test (cli/src/redact.test.ts, sandbox-hardening.test.ts,
  inference-router unit tests, cargo audit, npm audit, cargo fuzz)
  and provides a one-block reproduction recipe.

README.md
- Updated 'Admin token' row in Security Model: canonical
  'Authorization: Bearer', x-azureclaw-admin deprecation, constant-time
  compare, ROUTER_ADMIN_ALLOW_IPS / ADMIN_ALLOWED_ORIGINS allowlists.

docs/threat-model.md and CHANGELOG.md were already accurate and unchanged.

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant