#93 Audit remediation: SSRF allowlist, freepass sub-addressing, concurrent provisioning race, per-IP rate limit
Description
EditEARS SPEC:
- While FUTEX_ENV=prod, the system shall block private/loopback/reserved IPs on all user-supplied URL paths (webhook subscriptions + per-decision webhook_url) regardless of WEBHOOK_ALLOW_HOSTS entries that are host-only.
- Where WEBHOOK_ALLOW_HOSTS contains an exact host:port entry, the system shall exempt that specific target from the IP-class block.
- When normalizing a sender email for freepass, the system shall strip +tag sub-addressing for all domains except those in a blocklist of domains known to treat the local part literally.
- If concurrent freepass provisioning for the same new sender raises an IntegrityError, then the system shall rollback, re-query, and return already_active instead of surfacing a 503.
- When a freepass inbound request arrives via the webhook receiver, the system shall enforce a per-client-IP rate limit in addition to the per-address and global limits.
- The audit harness (audit/evaluations/run_all.sh) shall exit 0 after all fixes are applied.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...