Skip to content

security: bind outbound requests to configured origin - #1

Merged
chen21019 merged 1 commit into
mainfrom
security/codeql-critical-high-20260826
Aug 26, 2026
Merged

security: bind outbound requests to configured origin#1
chen21019 merged 1 commit into
mainfrom
security/codeql-critical-high-20260826

Conversation

@chen21019

Copy link
Copy Markdown

Fixes the open request-forgery findings by enforcing same-origin event and Rancher targets at the network sink. Error responses no longer log headers or bodies.

Validation: nested event-subscriber and go-rancher test suites pass.

@chen21019
chen21019 requested a review from a team as a code owner August 26, 2026 05:29
@chen21019
chen21019 merged commit 66c9522 into main Aug 26, 2026
6 checks passed
@chen21019
chen21019 deleted the security/codeql-critical-high-20260826 branch August 26, 2026 05:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant