Repository navigation
Conversation
…rm#6390) - Do not reflect arbitrary Origin headers when wildcard * is configured; return Access-Control-Allow-Origin: * instead. - Only include Access-Control-Allow-Credentials: true when the requesting Origin is explicitly whitelisted (not with wildcard or disallowed origins). - Remove hardcoded localhost development origins (127.0.0.1:3000, localhost:8080, 127.0.0.1:8080) from production middleware. - Gracefully handle empty allow_origin configuration and defensively trim whitespace. - Add comprehensive unit test suite in st2common/tests/unit/test_cors_middleware.py and update st2api functional tests.
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #6390 (CWE-346: Origin Validation Error in CORS middleware).
Problem
cfg.CONF.api.allow_originwas configured with*(wildcard),CorsMiddlewarereflected the incoming request'sOriginheader asAccess-Control-Allow-Origin: <origin>while simultaneously settingAccess-Control-Allow-Credentials: true. This CORS misconfiguration allowed arbitrary third-party websites visited by an authenticated user to perform authenticated, credential-bearing requests to the StackStorm API and read responses (tokens, execution results, datastore values, etc.).http://127.0.0.1:3000,http://localhost:8080, andhttp://127.0.0.1:8080into the allowed origin list on every request, bypassing administrator configurations in production environments.allow_originwas configured empty,list(origins)[0]resulted in an unhandledIndexError.Solution
Access-Control-Allow-Credentials: truewhen the incoming origin is explicitly listed inorigins(and not*).*is present inorigins, returnAccess-Control-Allow-Origin: *and omitAccess-Control-Allow-Credentials.origins, fall back to the default origin without granting credentials.Originheader is provided, do not grant credentials.Vary: OriginwheneverAccess-Control-Allow-Origindepends on the request origin (per CORS specifications).127.0.0.1:3000,localhost:8080, and127.0.0.1:8080fromCorsMiddleware. Allowed origins are now strictly derived from configuration.IndexError.allow_originhelp text inst2common/st2common/config.pynoting that*disables credentials.Testing
st2common/tests/unit/test_cors_middleware.pycovering:*) with untrusted origins (evil.com, subdomains,null,file://)OPTIONS) requests200,201,204,400,401,403,404,500)Varyheader handlingst2common/tests/unit/BUILDwithuses=[]for service-independent execution.PYTHONPATH="st2common" uv run --python 3.11 --with pytest --with mock --with-requirements st2common/requirements.txt pytest --noconftest st2common/tests/unit/test_cors_middleware.py -vst2api/tests/unit/controllers/v1/test_base.pyto assertAccess-Control-Allow-Origin: *, absence of credentials on wildcard, and rejection of hardcoded localhost origins.Closes #6390