Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 14 additions & 5 deletions pkg/workflow/engine_network_hooks.go
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
import (
"encoding/json"
"fmt"
"strconv"
"strings"
)

Expand All @@ -13,13 +14,20 @@
func (g *NetworkHookGenerator) GenerateNetworkHookScript(allowedDomains []string) string {
// Convert domain list to JSON for embedding in Python
// Ensure empty slice becomes [] not null in JSON
var domainsJSON []byte
var domainsJSON string
if allowedDomains == nil {
domainsJSON = []byte("[]")
domainsJSON = "[]"
} else {
domainsJSON, _ = json.Marshal(allowedDomains)
jsonBytes, _ := json.Marshal(allowedDomains)
domainsJSON = string(jsonBytes)
}

// Use strconv.Quote to safely escape the JSON string for Python
// This prevents any quote-related injection vulnerabilities (CWE-78, CWE-89, CWE-94)
quotedJSON := strconv.Quote(domainsJSON)

// Build the Python script using a safe template approach
// The JSON string is properly quoted and escaped, then parsed at runtime
return fmt.Sprintf(`#!/usr/bin/env python3
"""
Network permissions validator for Claude Code engine.
Expand All @@ -32,7 +40,8 @@
import re

# Domain allow-list (populated during generation)
ALLOWED_DOMAINS = %s
# JSON string is safely escaped using Go's strconv.Quote
ALLOWED_DOMAINS = json.loads(%s)

def extract_domain(url_or_query):
"""Extract domain from URL or search query."""
Expand Down Expand Up @@ -101,7 +110,7 @@
except Exception as e:
print(f"Network validation error: {e}", file=sys.stderr)
sys.exit(2) # Block on errors
`, string(domainsJSON))
`, quotedJSON)
Comment thread Fixed
}

// GenerateNetworkHookWorkflowStep generates a GitHub Actions workflow step that creates the network permissions hook
Expand Down