Skip to content

security(connectors): block env-secret egress on REST and Microsoft OAuth - #2012

Merged
FabioLeitao merged 1 commit into
mainfrom
fix/connector-env-secret-egress
Sep 28, 2026
Merged

FabioLeitao merged 1 commit into
mainfrom
fix/connector-env-secret-egress

Conversation

@FabioLeitao

@FabioLeitao FabioLeitao commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

What changes

#2006 — REST pass_from_env bypass (#1977)

  • Target-level pass_from_env, password_from_env, and user_from_env are treated as env-loaded credentials in _assert_rest_credential_hosts_allowlisted (same gate as auth.token_from_env / client_secret_from_env).
  • Env var names on REST targets must use prefixes DATA_BOAR_, REST_API_, or API_ (_validate_target_env_var_names).
  • When any of those keys are present, auth.allowed_hosts is required and must include every credential-bearing endpoint host (base_url, auth.token_url); attacker base_url can no longer be accepted as an implicit allowlist after the loader copies env → pass.

#2007 — Power BI / Dataverse OAuth token URL

What does not change

  • config/loader.py is unchanged: generic *_from_env resolution for databases, sinks, and lab configs is untouched.
  • Legitimate env names such as LAB_PG_PASSWORD, DB_PASS, SINK_DB_PASS, and documented PBI_SECRET continue to work for non-REST targets.
  • deploy/lab-smoke-stack/env.example is not part of this PR (local working-tree only).

Evidence

  • New regression tests use the real path load_config → REST _build_auth (tests/test_rest_connector_pass_from_env_loader.py).
  • Negative control: the attack-path loader tests fail on pre-fix main (implicit allowlist / missing gate); they pass on this branch.
  • Power BI / Dataverse: default template-generated token URL positive tests; attacker.example blocked before pinned_httpx_request.
  • ./scripts/check-all.sh — exit 0 (3182 passed).

Test plan

Closes #2006
Closes #2007


Note

High Risk
Changes secret-bearing outbound auth paths (REST env passwords and Microsoft OAuth token URLs); misconfiguration could break legitimate REST/Microsoft targets but prevents credential theft to attacker hosts.

Overview
Closes two credential-exfiltration gaps in HTTP connectors.

REST (#2006): Target-level pass_from_env, password_from_env, and user_from_env now count as env-loaded secrets in the same host-allowlist gate as auth env keys. Those env names must use DATA_BOAR_, REST_API_, or API_ prefixes, and auth.allowed_hosts is mandatory when any env credential is used—so a malicious base_url can’t be treated as an implicit allowlist after the loader copies env → pass.

Power BI / Dataverse (#2007): New assert_allowlisted_microsoft_token_url runs before posting client_secret to OAuth. Only https://login.microsoftonline.com is permitted; default tenant template URLs still work, but arbitrary auth.token_url hosts are rejected without hitting the network.

Regression tests cover loader → _build_auth for REST and token helpers for Microsoft connectors.

Reviewed by Cursor Bugbot for commit 721d992. Bugbot is set up for automated code reviews on this repo. Configure here.

…Auth

#2006: REST targets with pass_from_env/password_from_env/user_from_env are
treated as env-loaded credentials in _assert_rest_credential_hosts_allowlisted,
with the same DATA_BOAR_/REST_API_/API_ prefix rules as auth.token_from_env.
Loader still resolves DB/LAB env names unchanged; regression tests load YAML
via load_config then _build_auth.

#2007: Power BI and Dataverse call assert_allowlisted_microsoft_token_url
(login.microsoftonline.com only) before POSTing client_secret. Positive tests
use the default template-generated token URL.

Refs #2006
Refs #2007
@FabioLeitao

Copy link
Copy Markdown
Collaborator Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 721d992. Configure here.

@FabioLeitao
FabioLeitao merged commit f9d3661 into main Sep 28, 2026
30 checks passed
@FabioLeitao
FabioLeitao deleted the fix/connector-env-secret-egress branch September 28, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant