fix: close remaining security gaps, test fixes, frontend integration, event bus
Check Cross-Plugin Imports / check (push) Has been cancelled
Check Cross-Plugin Imports / check (push) Has been cancelled
- RCE: move _check_dangerous_imports() BEFORE exec_module() in plugins.py - verify_ws_origin: reject empty Origin header when CORS configured - Test: ai_app fixture with permission_registry init for ai_assistant - Test: login_client sets CSRF token + Origin as client default headers - Test: SESSION_COOKIE_SECURE=false override + get_settings.cache_clear() - Test: asyncio_default_test_loop_scope=session fixes event loop closed - Test: fix 15 assertions (paths, variables, auth expectations) - Frontend: integrate SavedFilterBar in ContactsList, Mail, Calendar - Frontend: integrate TagSelector in ContactsList, Mail, Calendar - Event Bus: add 4 subscribers in system_notif (conversation/participant/reaction) - Docs: update all analysis reports and FIX-PLAN-V2 to current state
This commit is contained in:
+4
-1
@@ -104,7 +104,10 @@ def verify_ws_origin(websocket) -> bool:
|
||||
return True
|
||||
origin = websocket.headers.get("origin", "")
|
||||
if not origin:
|
||||
return True # Non-browser clients don't send Origin
|
||||
# Non-browser clients (curl, etc.) don't send Origin.
|
||||
# Reject when CORS is configured — WebSocket should come from a browser.
|
||||
logger.warning("WebSocket connection rejected: missing Origin header")
|
||||
return False
|
||||
return origin in allowed_origins
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user