Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions changelog.d/fixes/ghsa-35fw-jx89-local-only-gates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- **fix(authz):** classify the 14 remaining spawn-capable `/api/cli-tools/*` routes (`all-statuses`, `status`, `detect` and the `claude/cline/codewhale/codex/crush/deepseek-tui/droid/kilo/openclaw/pi/smelt-settings` writers) and the `/api/skills/install` + `/api/skills/executions` pair as LOCAL_ONLY — they reach `child_process.spawn` transitively (`getCliRuntimeStatus()` / `detectAllTools()` / the skills sandbox) but only sat behind Tier 3 MANAGEMENT auth, which `requireLogin=false` waives; loopback/LAN enforcement now runs before any auth check, matching their already-gated siblings (GHSA-35fw-cv32-2373 — thanks Parth Narula; GHSA-jx89-f37j-pq89 — thanks Aeon). Tunnel-served dashboards lose the CLI Tools status badges, the same trade-off already accepted for grok/forge/jcode/qwen.
39 changes: 39 additions & 0 deletions docs/openapi.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3999,12 +3999,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get Claude CLI settings
x-loopback-only: true
responses:
"200":
description: Claude CLI configuration
post:
tags: [CLI Tools]
summary: Apply Claude CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4017,6 +4019,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset Claude CLI settings
x-loopback-only: true
responses:
"200":
description: Claude CLI settings reset
Expand All @@ -4025,12 +4028,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get Cline CLI settings
x-loopback-only: true
responses:
"200":
description: Cline CLI configuration
post:
tags: [CLI Tools]
summary: Apply Cline CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4043,6 +4048,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset Cline CLI settings
x-loopback-only: true
responses:
"200":
description: Cline CLI settings reset
Expand Down Expand Up @@ -4093,12 +4099,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get Codex CLI settings
x-loopback-only: true
responses:
"200":
description: Codex CLI configuration
post:
tags: [CLI Tools]
summary: Apply Codex CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4111,6 +4119,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset Codex CLI settings
x-loopback-only: true
responses:
"200":
description: Codex CLI settings reset
Expand All @@ -4119,12 +4128,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get Droid CLI settings
x-loopback-only: true
responses:
"200":
description: Droid CLI configuration
post:
tags: [CLI Tools]
summary: Apply Droid CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4137,6 +4148,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset Droid CLI settings
x-loopback-only: true
responses:
"200":
description: Droid CLI settings reset
Expand All @@ -4145,12 +4157,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get Kilo CLI settings
x-loopback-only: true
responses:
"200":
description: Kilo CLI configuration
post:
tags: [CLI Tools]
summary: Apply Kilo CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4163,6 +4177,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset Kilo CLI settings
x-loopback-only: true
responses:
"200":
description: Kilo CLI settings reset
Expand All @@ -4171,12 +4186,14 @@ paths:
get:
tags: [CLI Tools]
summary: Get OpenClaw CLI settings
x-loopback-only: true
responses:
"200":
description: OpenClaw CLI configuration
post:
tags: [CLI Tools]
summary: Apply OpenClaw CLI settings
x-loopback-only: true
requestBody:
required: true
content:
Expand All @@ -4189,6 +4206,7 @@ paths:
delete:
tags: [CLI Tools]
summary: Reset OpenClaw CLI settings
x-loopback-only: true
responses:
"200":
description: OpenClaw CLI settings reset
Expand Down Expand Up @@ -8256,6 +8274,7 @@ paths:
tags:
- CLI Tools
summary: Read Crush CLI OmniRoute config
x-loopback-only: true
description: Local-only. Reads the OmniRoute provider block in Crush's config.
x-internal: true
responses:
Expand All @@ -8265,6 +8284,7 @@ paths:
tags:
- CLI Tools
summary: Write Crush CLI OmniRoute config
x-loopback-only: true
description: Local-only. Registers OmniRoute as an `openai-compat` provider in Crush's config.
x-internal: true
responses:
Expand All @@ -8274,6 +8294,7 @@ paths:
tags:
- CLI Tools
summary: Remove OmniRoute from Crush CLI config
x-loopback-only: true
description: Local-only. Removes the OmniRoute provider block from Crush's config.
x-internal: true
responses:
Expand All @@ -8284,6 +8305,7 @@ paths:
tags:
- CLI Tools
summary: Read CodeWhale CLI OmniRoute config
x-loopback-only: true
description: >-
Local-only. Reads the OmniRoute config block from
`~/.codewhale/config.toml` (with `~/.deepseek/config.toml` legacy
Expand All @@ -8296,6 +8318,7 @@ paths:
tags:
- CLI Tools
summary: Write CodeWhale CLI OmniRoute config
x-loopback-only: true
description: Local-only. Writes the OmniRoute config block in CodeWhale TOML format.
x-internal: true
responses:
Expand All @@ -8305,6 +8328,7 @@ paths:
tags:
- CLI Tools
summary: Remove OmniRoute from CodeWhale CLI config
x-loopback-only: true
description: Local-only. Removes the OmniRoute config block from CodeWhale's config.
x-internal: true
responses:
Expand Down Expand Up @@ -8566,6 +8590,7 @@ paths:
tags:
- Cli tools
summary: "GET cli tools › all statuses"
x-loopback-only: true
responses:
"200":
description: OK
Expand Down Expand Up @@ -8597,20 +8622,23 @@ paths:
tags:
- Cli tools
summary: "DELETE cli tools › deepseek tui settings"
x-loopback-only: true
responses:
"200":
description: OK
get:
tags:
- Cli tools
summary: "GET cli tools › deepseek tui settings"
x-loopback-only: true
responses:
"200":
description: OK
post:
tags:
- Cli tools
summary: "POST cli tools › deepseek tui settings"
x-loopback-only: true
responses:
"200":
description: OK
Expand All @@ -8619,6 +8647,7 @@ paths:
tags:
- Cli tools
summary: "GET cli tools › detect"
x-loopback-only: true
responses:
"200":
description: OK
Expand Down Expand Up @@ -8791,20 +8820,23 @@ paths:
tags:
- Cli tools
summary: "DELETE cli tools › pi settings"
x-loopback-only: true
responses:
"200":
description: OK
get:
tags:
- Cli tools
summary: "GET cli tools › pi settings"
x-loopback-only: true
responses:
"200":
description: OK
post:
tags:
- Cli tools
summary: "POST cli tools › pi settings"
x-loopback-only: true
responses:
"200":
description: OK
Expand Down Expand Up @@ -8838,20 +8870,23 @@ paths:
tags:
- Cli tools
summary: "DELETE cli tools › smelt settings"
x-loopback-only: true
responses:
"200":
description: OK
get:
tags:
- Cli tools
summary: "GET cli tools › smelt settings"
x-loopback-only: true
responses:
"200":
description: OK
post:
tags:
- Cli tools
summary: "POST cli tools › smelt settings"
x-loopback-only: true
responses:
"200":
description: OK
Expand All @@ -8860,6 +8895,7 @@ paths:
tags:
- Cli tools
summary: "GET cli tools › status"
x-loopback-only: true
responses:
"200":
description: OK
Expand Down Expand Up @@ -11709,13 +11745,15 @@ paths:
tags:
- Skills
summary: "GET skills › executions"
x-loopback-only: true
responses:
"200":
description: OK
post:
tags:
- Skills
summary: "POST skills › executions"
x-loopback-only: true
responses:
"200":
description: OK
Expand All @@ -11724,6 +11762,7 @@ paths:
tags:
- Skills
summary: "POST skills › install"
x-loopback-only: true
responses:
"200":
description: OK
Expand Down
Loading
Loading