deepseek-harness/packages/client/connection/tests
creatixchu 01d68dee4e fix(connection): fence every /api request behind one browser-trust check
The only browser-trust guard covered host.pickDirectory, while the
consequential methods (session.prompt drives bash) accepted any Host —
open to DNS rebinding, where a rebound page reads and writes the API as
if same-origin and only the Host header betrays the attacker's domain.

The pickDirectory-specific loopback guard becomes a prefix-wide fence:
Host must be loopback or an exact host[:port] from the new trustedHosts
config, an attached Origin must equal that authority, and explicit
cross-site markers are refused; requests without browser markers (curl,
tests, native clients) pass, because without a browser there is no
confused deputy. The loopback-socket check is dropped — binding policy
expresses reachability, and the fence is not an auth layer. The Agent
Note records the full threat model and the alternatives.
2026-07-28 14:56:45 +08:00
..
api-helpers.spec.ts feat(gui): step1 skeleton — dsc web serves built web UI over booted harness host 2026-07-22 16:24:44 +08:00
api-request-trust.spec.ts fix(connection): fence every /api request behind one browser-trust check 2026-07-28 14:56:45 +08:00
client-apply.spec.ts ci: coverage 2026-07-22 17:23:59 +08:00
connection.spec.ts feat(gui): step1 skeleton — dsc web serves built web UI over booted harness host 2026-07-22 16:24:44 +08:00
fake-api.ts Merge remote-tracking branch 'origin/master' into worktree/web-session-model-selector 2026-07-28 00:39:24 +08:00
fixture-commands.spec.ts feat: slash system / input service / agent scope 2026-07-27 03:28:39 +08:00
fixture.spec.ts Merge remote-tracking branch 'origin/master' into worktree/web-session-model-selector 2026-07-27 17:18:29 +08:00
http-bridge.spec.ts feat(gui): add native workspace folder picker 2026-07-27 03:50:22 -07:00
node-half.spec.ts fix(connection): fence every /api request behind one browser-trust check 2026-07-28 14:56:45 +08:00