Commit 9a92737
harden(protocol): bound + charset-constrain the handshake session_id (#547)
The WebSocket handshake accepted an unbounded, arbitrary session_id from the
peer, then used it as a registry key, logged it, and hashed it into telemetry.
The plugin only ever produces "<slug>@<4hex>" (slug is [a-z0-9-]), so a
pattern of ^[A-Za-z0-9._@-]{1,128}$ rejects only malformed or non-plugin
clients while accepting every real id. A bad id now fails the handshake at the
Pydantic boundary instead of populating the registry.
Addresses review finding ST-4 (#527).
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>1 parent 5818173 commit 9a92737
2 files changed
Lines changed: 40 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
49 | | - | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
50 | 55 | | |
51 | 56 | | |
52 | 57 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
5 | 8 | | |
6 | 9 | | |
7 | 10 | | |
| |||
134 | 137 | | |
135 | 138 | | |
136 | 139 | | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
0 commit comments