Skip to content

fix(egress): refused requests log a hash of the requested host and path - #17

Merged
Optale-ops merged 2 commits into
mainfrom
fix/egress-rejection-host-hash
Oct 4, 2026
Merged

Optale-ops merged 2 commits into
mainfrom
fix/egress-rejection-host-hash

Conversation

@Optale-ops

Copy link
Copy Markdown
Owner

Asked for by Foundation after the #16 AX41 deploy. 35 passthrough refusals could not be traced: rejection lines had no destinationHost or pathHash, because those fields were set only after validation.

Change: right after the grant is read, the passthrough, package-transport and typed-fetch handlers record three fields from the requested URL: destinationHostHash (hashLabel of the lowercased host, the same 16-character sha256 base64url as the other hashes), pathHash (the same algorithm as the validated one) and queryPresent. Successful requests still overwrite destinationHost, pathHash and queryPresent with the validated values. The raw host is not logged for refusals, because sandbox code chooses it freely.

To read it: printf %s console-lab-callback.optale.com | sha256sum, i.e. base64url of the digest, first 16 characters. Compare that with destinationHostHash.

Tests: egress-gateway.test.ts asserts that a refused passthrough logs exactly one rejection, carrying the expected host and path hashes and not the host name. With the recording line disabled, that test fails. Full service suite: 720/720.

Deploy: this is egress_gateway only. Foundation can take it with the next AX41 gateway update; it changes no egress decision.

Egress audit lines carried destinationHost and pathHash only after a request
passed policy validation, so a HOST_NOT_ALLOWED refusal could not be traced
to a destination (seen on AX41 after the #16 deploy). The gateway now records
destinationHostHash (hashLabel of the lowercased host) plus pathHash and
queryPresent from the requested URL right after the grant is read, for HTTPS
passthrough, package transport and typed fetch. The host itself is not logged
for refusals, since sandbox code chooses it freely; an operator compares the
hash with hashLabel of a candidate host.
…n; tests select by route and outcome (#17 review)
@Optale-ops
Optale-ops merged commit 9bc83e1 into main Oct 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant