fix(egress): refused requests log a hash of the requested host and path - #17
Merged
Merged
Conversation
Egress audit lines carried destinationHost and pathHash only after a request passed policy validation, so a HOST_NOT_ALLOWED refusal could not be traced to a destination (seen on AX41 after the #16 deploy). The gateway now records destinationHostHash (hashLabel of the lowercased host) plus pathHash and queryPresent from the requested URL right after the grant is read, for HTTPS passthrough, package transport and typed fetch. The host itself is not logged for refusals, since sandbox code chooses it freely; an operator compares the hash with hashLabel of a candidate host.
…n; tests select by route and outcome (#17 review)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Asked for by Foundation after the #16 AX41 deploy. 35 passthrough refusals could not be traced: rejection lines had no
destinationHostorpathHash, because those fields were set only after validation.Change: right after the grant is read, the passthrough, package-transport and typed-fetch handlers record three fields from the requested URL:
destinationHostHash(hashLabelof the lowercased host, the same 16-character sha256 base64url as the other hashes),pathHash(the same algorithm as the validated one) andqueryPresent. Successful requests still overwritedestinationHost,pathHashandqueryPresentwith the validated values. The raw host is not logged for refusals, because sandbox code chooses it freely.To read it:
printf %s console-lab-callback.optale.com | sha256sum, i.e. base64url of the digest, first 16 characters. Compare that withdestinationHostHash.Tests:
egress-gateway.test.tsasserts that a refused passthrough logs exactly one rejection, carrying the expected host and path hashes and not the host name. With the recording line disabled, that test fails. Full service suite: 720/720.Deploy: this is egress_gateway only. Foundation can take it with the next AX41 gateway update; it changes no egress decision.