mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
Final batch of the CodeAnt re-scan (all adversarially verified): - app.py CSRF: the check ran only for JSON/form bodies (if sensitive), so a cross-site enctype=text/plain form POST (a browser 'simple request') skipped it — now enforced for every state-changing non-exempt /api/*. - app.py http-response-splitting (x2 redirect handlers): the untrusted request Host was reflected into the Location header; now stripped/charset-rejected before use (a configured domain always wins). - app.py CSP: dropped 'unsafe-eval' from script-src (Babel is pre-compiled, never runs in-browser). - SSRF: plugins/notifications _send_apprise (prefix blocklist missed decimal/IPv6/metadata) and nodes._safe_repo_url (root-run bash curl) now go through the url_security guard. - siem._row_to_target masks secret settings keys (token/password/api_key/secret/authorization) so a siem.view holder can't read the raw credential back out. - IDOR: power rate routes (get/upsert/delete, __default__ skipped), drift.acknowledge_event (gate on the event's cluster), schedules.get_schedules (was fail-open on empty clusters field -> now get_user_clusters). 277 passing. Residual (LOW, follow-up): vmware/xhm migration-list per-task cluster filter.