>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #99
Update issue details
Title *
Description
EARS SPEC: - Where a host is listed in WEBHOOK_ALLOW_HOSTS without a port, the Futex SSRF guard shall exempt that host on any port. - Where a host is listed with an explicit port, the Futex SSRF guard shall exempt that host only on that port. - If a host is not listed in WEBHOOK_ALLOW_HOSTS and resolves to a blocked address, then the Futex SSRF guard shall reject the URL. CAUSE: app/security/net_guard.py _is_allowlisted() iterates the allowlist but its only match branch is guarded by 'if ":" in entry'. A bare host entry can never match, so the allowlist silently does nothing. BLAST RADIUS: production runs WEBHOOK_ALLOW_HOSTS=127.0.0.1,localhost (both bare), so the exemption intended for internal webhook consumers has never worked — every loopback webhook target is rejected with 422. Pre-existing since commit 5195837; found because tests/e2e/test_full_flow.py fails on it. This is a config that looks correct and is inert.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel