#93 Audit remediation: SSRF allowlist, freepass sub-addressing, concurrent provisioning race, per-IP rate limit

closed high audit bug security Created 2026-07-30 00:40 · Updated 2026-07-30 00:53

Description

Edit
EARS SPEC: - While FUTEX_ENV=prod, the system shall block private/loopback/reserved IPs on all user-supplied URL paths (webhook subscriptions + per-decision webhook_url) regardless of WEBHOOK_ALLOW_HOSTS entries that are host-only. - Where WEBHOOK_ALLOW_HOSTS contains an exact host:port entry, the system shall exempt that specific target from the IP-class block. - When normalizing a sender email for freepass, the system shall strip +tag sub-addressing for all domains except those in a blocklist of domains known to treat the local part literally. - If concurrent freepass provisioning for the same new sender raises an IntegrityError, then the system shall rollback, re-query, and return already_active instead of surfacing a 503. - When a freepass inbound request arrives via the webhook receiver, the system shall enforce a per-client-IP rate limit in addition to the per-address and global limits. - The audit harness (audit/evaluations/run_all.sh) shall exit 0 after all fixes are applied.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...