Skip to content

fix(adapters): validate external request targets - #876

Merged
bensabic merged 1 commit into
mainfrom
fix/security-network-boundaries
Aug 31, 2026
Merged

bensabic merged 1 commit into
mainfrom
fix/security-network-boundaries

Conversation

@bensabic

Copy link
Copy Markdown
Collaborator

Adapters now reject untrusted destinations before sending credentials, message content, or attachment requests.

Teams Connector and Graph calls stay on known Microsoft hosts, Instagram downloads stay on trusted Meta hosts, and Slack response URLs are checked before use.

XChat now handles CRC challenges itself and rejects tokens that could be reused to forge webhook signatures.

Signed-off-by: Ben Sabic <bensabic@users.noreply.github.com>
@bensabic
bensabic requested a review from a team as a code owner August 31, 2026 05:58
@vercel

vercel Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
chat Ready Ready Preview, v0 Aug 31, 2026 5:59am
chat-sdk-nextjs-chat Ready Ready Preview, v0 Aug 31, 2026 5:59am

@gr2m gr2m left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changes look good.

Consider hardening sendSlackResponseUrl() as well, it still POSTs its message payload to any caller-supplied URL. I didn't dig deeper into whether that's another security concern, maybe a note in the docs will suffice to warn users not to blindly pass through user-provided URLs to it?

@bensabic
bensabic merged commit 7609d8f into main Aug 31, 2026
19 checks passed
@bensabic
bensabic deleted the fix/security-network-boundaries branch August 31, 2026 17:13
patrick-chinchill added a commit to Chinchill-AI/chat-sdk-python that referenced this pull request Sep 30, 2026
…ereign allowlists (#221)

Teams auth extension points: a custom token factory that beats every client-secret source, a webhook_verifier run on the exact raw body before parsing (replacing SDK JWT validation), a callable app_id resolved once in initialize(), and sovereign-cloud service-URL/Graph host allowlists.
Upstream commits ported: e06b4b60 (vercel/chat#732, chat@4.35.0), portable parts of 139d337e (vercel/chat#930, chat@4.41.0; Vercel Connect N/A), Teams part of 7609d8f6 (vercel/chat#876, chat@4.40.0).
Divergences: App subclass enforces token-factory precedence over CLIENT_SECRET (Python SDK credential order); ValueError instead of TeamsApiError for untrusted URLs; broader wildcard service-URL allowlist kept. Merged with #250: in verifier mode the Bot Framework issuer pre-check is bypassed, as upstream.
Consumer impact: all new options are opt-in; an empty webhook body now returns 400 (was parsed as {}).
Closes #221

This branch was successfully deployed

2 active deployments
Preview – chat — 40942614 Deployed Aug 31, 2026 by vercel[bot]
Preview – chat-sdk-nextjs-chat — 40942614 Deployed Aug 31, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants