Skip to content

fix(relay): strip unsafe forwarded headers - #11533

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
pacocartones:fix/oss026-relay-header-denylist
Aug 25, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
pacocartones:fix/oss026-relay-header-denylist

Conversation

@pacocartones

Copy link
Copy Markdown
Contributor

Applies one canonical denylist across generated Cloudflare, Vercel and Deno relays so hop-by-hop, framing, proxy-auth and relay-control headers are not forwarded upstream. Tests: 3/3 contract plus 30/30 related SSRF pass; focused ESLint, build-scope and diff checks pass. ⚠️ base-red inherited: #11449.

@pacocartones
pacocartones force-pushed the fix/oss026-relay-header-denylist branch from ba88429 to b653e78 Compare August 25, 2026 15:17
@diegosouzapw
diegosouzapw merged commit 28601b4 into diegosouzapw:release/v3.8.51 Aug 25, 2026
7 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Validated in a combined 10-PR batch worktree off release/v3.8.51 tip.
- Focused test: tests/unit/generated-relay-header-denylist.test.ts — 3/3 contract pass plus 30/30 related SSRF tests
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity gates — all OK
- Full-repo lint: 503 pre-existing problems confirmed identical on the pure release/v3.8.51 tip — unrelated to this diff

⚠️ base-red inherited: diegosouzapw#11449

Thanks for applying one canonical header denylist across the generated Cloudflare/Vercel/Deno relays so hop-by-hop, framing, and proxy-auth/relay-control headers stop leaking upstream.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants