Repository navigation
security(connectors): block env-secret egress on REST and Microsoft OAuth - #2012
Merged
Merged
Conversation
…Auth #2006: REST targets with pass_from_env/password_from_env/user_from_env are treated as env-loaded credentials in _assert_rest_credential_hosts_allowlisted, with the same DATA_BOAR_/REST_API_/API_ prefix rules as auth.token_from_env. Loader still resolves DB/LAB env names unchanged; regression tests load YAML via load_config then _build_auth. #2007: Power BI and Dataverse call assert_allowlisted_microsoft_token_url (login.microsoftonline.com only) before POSTing client_secret. Positive tests use the default template-generated token URL. Refs #2006 Refs #2007
Collaborator
Author
|
bugbot run |
Contributor
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 721d992. Configure here.
2 of 3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
What changes
#2006 — REST
pass_from_envbypass (#1977)pass_from_env,password_from_env, anduser_from_envare treated as env-loaded credentials in_assert_rest_credential_hosts_allowlisted(same gate asauth.token_from_env/client_secret_from_env).DATA_BOAR_,REST_API_, orAPI_(_validate_target_env_var_names).auth.allowed_hostsis required and must include every credential-bearing endpoint host (base_url,auth.token_url); attackerbase_urlcan no longer be accepted as an implicit allowlist after the loader copies env →pass.#2007 — Power BI / Dataverse OAuth token URL
assert_allowlisted_microsoft_token_url(connectors/microsoft_identity.py) runs before POSTingclient_secret.login.microsoftonline.comis permitted (vendor host allowlist, HubSpot [P1][security] hubspot_connector: base_url sem allowlist de host permite exfiltração do Bearer token #1607 style). Default template URLs from Power BI / Dataverse pass; arbitrary publicauth.token_urlhosts do not.What does not change
config/loader.pyis unchanged: generic*_from_envresolution for databases, sinks, and lab configs is untouched.LAB_PG_PASSWORD,DB_PASS,SINK_DB_PASS, and documentedPBI_SECRETcontinue to work for non-REST targets.deploy/lab-smoke-stack/env.exampleis not part of this PR (local working-tree only).Evidence
load_config→ REST_build_auth(tests/test_rest_connector_pass_from_env_loader.py).main(implicit allowlist / missing gate); they pass on this branch.attacker.exampleblocked beforepinned_httpx_request../scripts/check-all.sh— exit 0 (3182 passed).Test plan
tests/test_rest_connector_pass_from_env_loader.pytests/test_rest_connector_auth_allowlist.py(existing security(MEDIUM): REST connector base_url/token_url has no host allowlist — Bearer/client_secret exfil to public host #1977)tests/test_powerbi_dataverse_http_surfaces.py(new security(HIGH): PowerBI connector POSTs client_secret_from_env to any public token_url, same gap #1977 fixed for REST #2007 cases)./scripts/check-all.shCloses #2006
Closes #2007
Note
High Risk
Changes secret-bearing outbound auth paths (REST env passwords and Microsoft OAuth token URLs); misconfiguration could break legitimate REST/Microsoft targets but prevents credential theft to attacker hosts.
Overview
Closes two credential-exfiltration gaps in HTTP connectors.
REST (#2006): Target-level
pass_from_env,password_from_env, anduser_from_envnow count as env-loaded secrets in the same host-allowlist gate as auth env keys. Those env names must useDATA_BOAR_,REST_API_, orAPI_prefixes, andauth.allowed_hostsis mandatory when any env credential is used—so a maliciousbase_urlcan’t be treated as an implicit allowlist after the loader copies env →pass.Power BI / Dataverse (#2007): New
assert_allowlisted_microsoft_token_urlruns before postingclient_secretto OAuth. Onlyhttps://login.microsoftonline.comis permitted; default tenant template URLs still work, but arbitraryauth.token_urlhosts are rejected without hitting the network.Regression tests cover loader →
_build_authfor REST and token helpers for Microsoft connectors.Reviewed by Cursor Bugbot for commit 721d992. Bugbot is set up for automated code reviews on this repo. Configure here.