Skip to content

fix: close the critical and high review findings - #49

Merged
guillaumegay13 merged 1 commit into
mainfrom
fix/review-findings
Sep 26, 2026
Merged

guillaumegay13 merged 1 commit into
mainfrom
fix/review-findings

Conversation

@guillaumegay13

Copy link
Copy Markdown
Contributor

✨ What changed

  • Capturing a failed response stops after 1 s (httpx, requests, aiohttp, urllib), the rest stays with the caller
  • A retry with a new body drops transfer-encoding, so it never carries two framings
  • A failed install (a bad HTTPS_PROXY, say) is rolled back with a warning, the app keeps running
  • A patched retry URL goes through the allowlist and denylist
  • Filter paths are compared decoded, with . and .. resolved

💭 Why

Findings from a full-repo review (High). A server trickling a 4xx could stall a streaming caller, and /v1/%73ecret got past a /v1/secret deny rule.

📝 Notes

tests/fixtures/url-filter.json gained encoded-path cases, the same in node, python and php.
Credential masking findings are left for mnfst/http-redact.

@guillaumegay13
guillaumegay13 merged commit b875ecd into main Sep 26, 2026
4 checks passed
@guillaumegay13
guillaumegay13 deleted the fix/review-findings branch September 26, 2026 22:15
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant