Skip to content

fix: allowlist credential URLs, block fetch redirects, harden error redaction - #15

Merged
ScriptedAlchemy merged 3 commits into
ScriptedAlchemy:mainfrom
lewismarshall:fix/gateway-url-allowlist
Sep 15, 2026
Merged

ScriptedAlchemy merged 3 commits into
ScriptedAlchemy:mainfrom
lewismarshall:fix/gateway-url-allowlist

Conversation

@lewismarshall

@lewismarshall lewismarshall commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Stops sending the live gateway / EnsureSandBox bearer token to unexpected hosts or across HTTP redirects, and hardens stderr redaction so error bodies are less likely to leak credentials.

Changes

  1. Gateway URL allowlist (src/url-policy.js)
    • Default: https only on *.cursor.sh / *.cursor.com (and apex).
    • GROK_BOT_ALLOW_LOCAL_GATEWAY=1 for http(s)://127.0.0.1, localhost, ::1.
    • GROK_BOT_ALLOW_ANY_GATEWAY=1 break-glass (documented as unsafe).
    • Applied on env override, app-session load, EnsureSandBox response, and each gatewayCall.
  2. redirect: "error" on both fetch sites (ensureSandbox, gatewayCall).
  3. Key-based secret redaction via redactSecrets() in fail() and gateway error paths (broader than the old Bearer-only regex).

Test plan

  • npm test (includes new test/url-policy.test.js)
  • Smoke: normal macOS app-session gbot bots list
  • Smoke: GROK_BOT_ALLOW_LOCAL_GATEWAY=1 with local gateway
  • Confirm rejected host fails closed without sending the token

Notes for maintainers

If production box gateway hosts are not under *.cursor.sh / *.cursor.com, please say so in review and we can extend the allowlist before merge (or document the required env opt-in).

@changeset-bot

changeset-bot Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f70709a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
grok-bot-cli Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

lewismarshall and others added 2 commits September 15, 2026 00:36
Validate gateway/backend hosts before sending tokens, set redirect:error
on both fetch sites, and redact secrets in error output more thoroughly.
@ScriptedAlchemy
ScriptedAlchemy force-pushed the fix/gateway-url-allowlist branch from 2892b13 to 2e62663 Compare September 15, 2026 00:37
Backend EnsureSandBox URLs admit only *.cursor.sh / *.cursor.com so a
Cursor access token cannot be pointed at *.cursorvm.com. Gateway policy
keeps the box family. Redact Cookie/Set-Cookie and full Authorization
values; drop 0.0.0.0 from local hosts; warn once for break-glass env.
@ScriptedAlchemy
ScriptedAlchemy merged commit ef6ce79 into ScriptedAlchemy:main Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants