Skip to content

fix: Validate clone destinations before attaching installation tokens - #111

Merged
julio-rocketchat merged 2 commits into
developfrom
fix/validate-clone-destinations
Sep 26, 2026
Merged

julio-rocketchat merged 2 commits into
developfrom
fix/validate-clone-destinations

Conversation

@julio-rocketchat

Copy link
Copy Markdown
Member

Summary

  • Validate clone URLs before attaching an installation token or spawning Git.
  • Permit HTTPS github.com destinations with the default port; reject other hosts/protocols, existing credentials, query strings, and fragments.
  • Encode token delimiters through the URL API and keep setup debug output credential-free.

Verification

  • Node 22: build, typecheck, lint, configuration validation, and all 632 tests passed.
  • Added 13 regression cases covering destination spoofing, unsupported transports, invalid URLs, and token delimiter encoding.
  • Reviewed the complete patch for credential exposure and URL-parser bypasses; Gitleaks scan of the staged patch passed.

Compatibility

This explicitly limits authenticated clones to github.com, consistent with the current GitHub API integration. No new configuration or dependencies.

@julio-rocketchat

Copy link
Copy Markdown
Member Author

CI follow-up: the shared install failure was reproduced in an isolated Node 22 container. With maintainer approval, this branch now uses npm ci instead of deleting the lockfile and resolving a fresh dependency graph. This is the only CI change; GitHub checks are rerunning.

@julio-rocketchat
julio-rocketchat merged commit 496f508 into develop Sep 26, 2026
3 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant