fix(security): never send raw exception text from the Responses WebSocket proxy (Hard Rule #12) - #15073
Merged
Conversation
…cket proxy (Hard Rule #12) responses-ws-proxy.mjs ships as dist/responses-ws-proxy.mjs (a server-ws.mjs dependency). Two paths wrote raw exception text to the client: - a failed upgrade returned error.message in the 500 body (CodeQL js/stack-trace-exposure + js/xss-through-exception) — paths and stack frames; - an upstream connect failure sent error.message in the response.failed frame — which can carry the configured upstream proxy URL with its credentials, or internal addresses. Both now return a fixed message; the detail stays in the server log and in the server-side request history. Tests reproduce both leaks (the second shows user:s3cret@10.0.0.9 reaching the client) and fail on the old code.
Owner
Author
|
Validation on 192.168.0.113 (5fba0e6): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves CodeQL alerts #1021 (
js/xss-through-exception) and #1022 (js/stack-trace-exposure), both onscripts/dev/responses-ws-proxy.mjs:333.That file is not dev-only: it ships as
dist/responses-ws-proxy.mjs, a dependency of the standaloneserver-ws.mjs. Hard Rule #12 therefore applies.Two leaks, one class
error.message, which can include filesystem paths and stack frames.response.failedframe sent to the client carriederror.messagefrom the upstream connect. That text can include the configured upstream proxy URL with its credentials and internal addresses. The new test showshttp://user:s3cret@10.0.0.9:3128reaching the client before the fix.Both now return a fixed message: "Responses WebSocket proxy failed" and "Upstream WebSocket connection failed". The error code does not change. The raw detail stays server-side, in the server log for the upgrade path and in the request history for the connect path.
Validation
tests/unit/responses-ws-proxy-error-sanitization.test.mjs(2 cases). Both fail on the old code.responses-ws-proxy*suites pass locally. The full set runs on 192.168.0.113; results are in a comment below.