ODS host must resolve to a public address - #139
Merged
Merged
Conversation
The ODS connection test requests the user-supplied host and the auth endpoint named in its response. Outside of dev, these requests now go only to http(s) destinations that resolve to public addresses, checked at connect time and on each redirect. Address classification uses ipaddr.js (IANA special-purpose ranges). Requests also get a 10s overall deadline, and refused requests are logged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The host field is user-entered and may contain userinfo, query parameters, or text pasted into the wrong field, so the refused-request warning now records just the URL's origin. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
⏳ I'm reviewing this pull request for security vulnerabilities and code quality issues. I'll provide an update when I'm done |
Contributor
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
✅ I finished the code review, and left comments with the issues I found. |
edandylytics
commented
Sep 30, 2026
| "express-session": "^1.19.0", | ||
| "framer-motion": "^11.2.12", | ||
| "ignore": "^5.3.1", | ||
| "ipaddr.js": "^2.5.0", |
Collaborator
Author
There was a problem hiding this comment.
ipaddr was already pulled in as a dependency of @nestjs/platform-express -- now it's a direct dependency.
…odule load order EdfiService now uses the globally provided AppConfigService rather than importing AppConfigModule, which had changed which instance the app resolves. The guard tests spy on ipaddr.process instead of mocking the module, so they pass when the app is loaded first, as in the integration run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
rtavernaea
approved these changes
Sep 30, 2026
The connection test sends the ODS client credentials, so outside of dev the host, the auth endpoint and any redirects must use https. With http no longer reachable there, the http agent is removed. Tests now run the local ODS over https using a generated self-signed certificate (selfsigned, dev only). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
rtavernaea
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR ensures that the ODS host and auth endpoints resolve to public addresses.