Skip to content

fix: harden MSP domain hostname validation - #19

Open
rtrappman-dev wants to merge 5 commits into
firewalla:mainfrom
rtrappman-dev:fix/MSP-domain/hostname-allowlist-bypass
Open

rtrappman-dev wants to merge 5 commits into
firewalla:mainfrom
rtrappman-dev:fix/MSP-domain/hostname-allowlist-bypass

Conversation

@rtrappman-dev

Copy link
Copy Markdown

Summary

Harden MSP domain validation to prevent attacker-controlled URL syntax from bypassing the *.firewalla.net allowlist and redirecting requests containing the MSP API token to an unintended host.

Security Impact

The previous validation relied on a raw string suffix check:

cleanDomain.endsWith('.firewalla.net')

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant