Skip to content

Reject nonlocal dashboard requests - #125

Merged
Deicyde merged 3 commits into
mainfrom
fix/dashboard-origin-guard
Oct 5, 2026
Merged

Deicyde merged 3 commits into
mainfrom
fix/dashboard-origin-guard

Conversation

@Deicyde

@Deicyde Deicyde commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • require exactly one Host header matching the dashboard's literal loopback listener and bound port
  • reject cross-origin browser requests unless their HTTP Origin matches that same listener
  • apply the guard before loading claims or serving static files for both GET and HEAD
  • test DNS-rebinding Host values on both surfaces and hostile Origins on both request methods

Binding to 127.0.0.1 does not prevent DNS rebinding: before this change, a request with Host: attacker.example received the private static site and live claim JSON with HTTP 200. The request-level authority check closes that boundary while preserving direct 127.0.0.1 and localhost use.

The HEAD guard matters because SimpleHTTPRequestHandler implements it separately from GET; guarding only do_GET left static metadata available to a nonlocal authority.

Validation

At exact head 59e52996:

  • full dashboard suite: 14 passed
  • make lint: pass
  • make check-example: pass
  • exact-head GitHub Python 3.10/3.13, Windows, real Lean, and CLA: all pass

#137 has landed the former README baseline fix.

Fixes F29 from #92's adversarial review.

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Meta Open Source bot. label Oct 5, 2026
@Deicyde Deicyde added blocked Waiting for prerequisite work before implementation can proceed review: ready Review complete with no known merge blockers labels Oct 5, 2026
@Deicyde
Deicyde marked this pull request as ready for review October 5, 2026 21:42
@Deicyde

Deicyde commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Exact-head review is complete at eefe1597. Host and Origin authority are checked before both GET and HEAD response surfaces, including static content and the live endpoint. The full dashboard suite passes (14 tests), as do lint, the executable example, Python 3.10, Windows, both real-Lean runs, and CLA. The duplicate cancelled jobs are runner shutdowns, and the other Python failure is current main's stale README assertion fixed by #96/#137. No feature-code blocker remains.

@Deicyde Deicyde removed the blocked Waiting for prerequisite work before implementation can proceed label Oct 5, 2026
@Deicyde

Deicyde commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

The refreshed exact head 59e52996 is fully green: Python 3.10/3.13, Windows, real Lean, and CLA all pass. It is mergeable and has no known code or ordering blocker.

@Deicyde
Deicyde merged commit 299c3fa into main Oct 5, 2026
9 checks passed
@Deicyde
Deicyde deleted the fix/dashboard-origin-guard branch October 5, 2026 22:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Meta Open Source bot. review: ready Review complete with no known merge blockers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant