#99 FTX-99: WEBHOOK_ALLOW_HOSTS is inert for bare hosts — allowlist only matches host:port entries
Description
EditEARS SPEC:
- Where a host is listed in WEBHOOK_ALLOW_HOSTS without a port, the Futex SSRF guard shall exempt that host on any port.
- Where a host is listed with an explicit port, the Futex SSRF guard shall exempt that host only on that port.
- If a host is not listed in WEBHOOK_ALLOW_HOSTS and resolves to a blocked address, then the Futex SSRF guard shall reject the URL.
CAUSE: app/security/net_guard.py _is_allowlisted() iterates the allowlist but its only match branch is guarded by 'if ":" in entry'. A bare host entry can never match, so the allowlist silently does nothing.
BLAST RADIUS: production runs WEBHOOK_ALLOW_HOSTS=127.0.0.1,localhost (both bare), so the exemption intended for internal webhook consumers has never worked — every loopback webhook target is rejected with 422. Pre-existing since commit 5195837; found because tests/e2e/test_full_flow.py fails on it. This is a config that looks correct and is inert.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...