Skip to content

fix(security): harden outbound destination validation - #1493

Merged
Wikid82 merged 4 commits into
developmentfrom
hotfix/outbound-destination-hardening
Oct 6, 2026
Merged

Wikid82 merged 4 commits into
developmentfrom
hotfix/outbound-destination-hardening

Conversation

@Wikid82

@Wikid82 Wikid82 commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Summary

Hardens how Charon validates destinations for outbound requests by consolidating the address checks into one shared policy used by every caller, and tightening the defaults.

  • Commit 1 and 2 are refactors with no behavior change (parity tests cover the old and new option sets).
  • Commit 3 flips the defaults and removes the superseded options.
  • Features that legitimately target overlay-network addresses (uptime checks, remote storage, webhooks, notification providers) keep working.
  • No settings, schema, API, or UI changes.

Testing

  • Unit tests for the shared policy, per-caller wiring, and boundary addresses.
  • Backend build, full test run, lint, and coverage gates pass locally.

Claude Code was used to help produce this change.

Route address checks through one shared policy type.
Declare destination allowances explicitly at each call site.
Apply a single shared address policy, secure by default, to outbound destination checks.
@codecov

codecov Bot commented Oct 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

✅ Supply Chain Verification Results

✅ PASSED

📦 SBOM Summary

  • Components: 1870

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@Wikid82
Wikid82 merged commit 8b0d0c2 into development Oct 6, 2026
49 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants