mirror of
https://github.com/moltbot/moltbot.git
synced 2026-03-08 06:54:24 +00:00
* fix(msteams): add SSRF protection to attachment downloads via redirect and DNS validation The attachment download flow in fetchWithAuthFallback() followed redirects automatically on the initial fetch without any allowlist or IP validation. This allowed DNS rebinding attacks where an allowlisted domain (e.g. evil.trafficmanager.net) could redirect or resolve to a private IP like 169.254.169.254, bypassing the hostname allowlist entirely (issue #11811). This commit adds three layers of SSRF protection: 1. safeFetch() in shared.ts: a redirect-safe fetch wrapper that uses redirect: "manual" and validates every redirect hop against the hostname allowlist AND DNS-resolved IP before following it. 2. isPrivateOrReservedIP() + resolveAndValidateIP() in shared.ts: rejects RFC 1918, loopback, link-local, and IPv6 private ranges for both initial URLs and redirect targets. 3. graph.ts SharePoint redirect handling now also uses redirect: "manual" and validates resolved IPs, not just hostnames. The initial fetch in fetchWithAuthFallback now goes through safeFetch instead of a bare fetch(), ensuring redirects are never followed without validation. Includes 38 new tests covering IP validation, DNS resolution checks, redirect following, DNS rebinding attacks, redirect loops, and protocol downgrade blocking. * fix: address review feedback on SSRF protection - Replace hand-rolled isPrivateOrReservedIP with SDK's isPrivateIpAddress which handles IPv4-mapped IPv6, expanded notation, NAT64, 6to4, Teredo, octal IPv4, and fails closed on parse errors - Add redirect: "manual" to auth retry redirect fetch in download.ts to prevent chained redirect attacks bypassing SSRF checks - Add redirect: "manual" to SharePoint redirect fetch in graph.ts to prevent the same chained redirect bypass - Update test expectations for SDK's fail-closed behavior on malformed IPs - Add expanded IPv6 loopback (0:0:0:0:0:0:0:1) test case * fix: type fetchMock as typeof fetch to fix TS tuple index error * msteams: harden attachment auth and graph redirect fetch flow * changelog(msteams): credit redirect-safeFetch hardening contributors --------- Co-authored-by: Vincent Koc <vincentkoc@ieee.org>