fix(adapters): validate external request targets - #876
Merged
Merged
Conversation
Signed-off-by: Ben Sabic <bensabic@users.noreply.github.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
bensabic
enabled auto-merge (squash)
August 31, 2026 06:03
gr2m
approved these changes
Aug 31, 2026
gr2m
left a comment
There was a problem hiding this comment.
changes look good.
Consider hardening sendSlackResponseUrl() as well, it still POSTs its message payload to any caller-supplied URL. I didn't dig deeper into whether that's another security concern, maybe a note in the docs will suffice to warn users not to blindly pass through user-provided URLs to it?
patrick-chinchill
added a commit
to Chinchill-AI/chat-sdk-python
that referenced
this pull request
Sep 30, 2026
…ereign allowlists (#221) Teams auth extension points: a custom token factory that beats every client-secret source, a webhook_verifier run on the exact raw body before parsing (replacing SDK JWT validation), a callable app_id resolved once in initialize(), and sovereign-cloud service-URL/Graph host allowlists. Upstream commits ported: e06b4b60 (vercel/chat#732, chat@4.35.0), portable parts of 139d337e (vercel/chat#930, chat@4.41.0; Vercel Connect N/A), Teams part of 7609d8f6 (vercel/chat#876, chat@4.40.0). Divergences: App subclass enforces token-factory precedence over CLIENT_SECRET (Python SDK credential order); ValueError instead of TeamsApiError for untrusted URLs; broader wildcard service-URL allowlist kept. Merged with #250: in verifier mode the Bot Framework issuer pre-check is bypassed, as upstream. Consumer impact: all new options are opt-in; an empty webhook body now returns 400 (was parsed as {}). Closes #221
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adapters now reject untrusted destinations before sending credentials, message content, or attachment requests.
Teams Connector and Graph calls stay on known Microsoft hosts, Instagram downloads stay on trusted Meta hosts, and Slack response URLs are checked before use.
XChat now handles CRC challenges itself and rejects tokens that could be reused to forge webhook signatures.