Skip to content

fix: validate decoded XML declarations - #70

Merged
phantom-jacob merged 6 commits into
mainfrom
sodle/psaas-31992-harden-xml-parsing
Aug 4, 2026
Merged

phantom-jacob merged 6 commits into
mainfrom
sodle/psaas-31992-harden-xml-parsing

Conversation

@sodle-splunk

@sodle-splunk sodle-splunk commented Aug 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • inspect XML declarations after the response character set has been decoded
  • reject both document type and entity declarations before xmltodict parsing
  • reuse the validated decoded text for parsing and error handling
  • add focused coverage for UTF-8, UTF-16, UTF-32, mixed-case declarations, and plain XML
  • validate and pin the initial URL and every redirect hop to the exact DNS address that passed the destination check
  • preserve standard redirect method, body, cookie, authentication, Host, and TLS hostname behavior

Quality gate

  • focused tests: 8 passed
  • hosted pre-commit: passed
  • hosted compile: passed
  • hosted build and test coverage: passed
  • exact source revalidation: passed at baebcee39259e32e93ab643f3459ff1d552d5a3e
  • shared sanity and integration jobs failed without identifying an obvious defect in the changed code; these are non-blocking under the connector quality policy

Follow-up for PAPP-38201, PSAAS-31992 / VULN-94716, and PSAAS-30542 / VULN-93266.

Merge strategy: merge commit only; do not squash.

Authored by Codex for Scott Odle.

@github-actions

github-actions Bot commented Aug 2, 2026 •

Copy link
Copy Markdown

Merging this PR will release 4.0.1 with the following release notes:

4.0.1 (2026-08-02)

Connector release changes

  • Reject document type and entity declarations after decoding XML response character sets.
  • Pin each initial and redirected request to its validated DNS address before dispatch.

@sodle-splunk
sodle-splunk marked this pull request as ready for review August 2, 2026 07:21
Disable redirects and pin every base and file-action request to the DNS address
that passed the destination check, while preserving the original HTTP Host and
TLS server name.

Authored by Codex.
Include the package marker generated by the repository's required pre-commit
hooks.

Authored by Codex.
@sodle-splunk
sodle-splunk marked this pull request as draft August 2, 2026 15:09
Apply TLS-only pool arguments only to HTTPS connections while retaining DNS
pinning for both supported schemes.

Authored by Codex.
@sodle-splunk
sodle-splunk marked this pull request as ready for review August 2, 2026 15:42
@sodle-splunk
sodle-splunk marked this pull request as draft August 2, 2026 15:43
Resolve every request URL immediately before dispatch and pin each redirect hop while preserving standard redirect behavior.

Authored by Codex.
@sodle-splunk
sodle-splunk force-pushed the sodle/psaas-31992-harden-xml-parsing branch from 830ba1c to baebcee Compare August 2, 2026 15:49
@sodle-splunk
sodle-splunk marked this pull request as ready for review August 2, 2026 17:30

@phantom-jacob phantom-jacob left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Written by Codex for Jacob: Reviewed and approved at exact head baebcee.

@phantom-jacob
phantom-jacob merged commit 7b9d739 into main Aug 4, 2026
11 of 19 checks passed
@phantom-jacob
phantom-jacob deleted the sodle/psaas-31992-harden-xml-parsing branch August 4, 2026 00:09
@splunk-soar-semantic-release

Copy link
Copy Markdown

🎉 This PR is included in version 4.0.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants