fix(ned): normalize Host/Origin ports and trailing dots; warn on deprecated tokens #84
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "pr/ned-security-followup"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-up to #83, addressing review feedback on the CSRF/DNS-rebinding guard.
Changes
Scheme-aware port normalization (
ned/handler.py) — the Origin port comparison now resolves implicit scheme defaults (http→80,https→443), so a default-port origin (e.g. a page athttp://127.0.0.1) can no longer masquerade as a listener on a non-default port even when the hostname matches. The request port is still only compared when explicit — a reverse proxy (Tailscale Serve, nginx) legitimately changes ports (https:443 → backend :8080) and its Host header carries no port, so strict 443-vs-backend equality would 403 the PWA behind them. (The reviewer'sreq_port or 80formulation would break exactly that; this is the corrected version.)Host trailing-dot normalization (
ned/handler.py) —_parse_host_headernowrstrip(".")s the hostname, matching the allowlist and Origin normalization. curl and some proxies send FQDNHost:headers with a trailing dot (host.), which previously produced false 403s.Deprecated-token startup warning (
ned/main.py) — whensettings.web_token/--tokenis non-empty, NED logs that tokens are deprecated: the web/PWA client requires a tokenless listener (browsers can't sendAuthorizationon navigation;?token=is gone), so a non-empty token silently locks the PWA out while still serving non-browser clients via the header.agent.md docs — refreshed stale bearer-token claims (auth via tailnet ACLs, header-only deprecated tokens, Host/Origin enforcement).
Note on agent.md
agent.mdhas uncommitted work-in-progress edits in the local working tree (unrelated rewrite). This PR stages only a minimal prose fix on the committed version; the WIP is left untouched locally.Verification
subprocess.rundiscards stderr on timeout)ned/client.pyerrors are pre-existing on mainsubprocessunused import inned/main.pyReview steps
git checkout pr/ned-security-followupQT_QPA_PLATFORM=offscreen ~/.local/share/pipx/venvs/lazarus-mail/bin/python -m pytest tests/test_ned_security.py -qned --host 127.0.0.1 --token secret→ observe the deprecation warning at startup.