feat(notifications): define bounded W66 delivery contracts - #240
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review Please review exact W66 Slice 1 head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2460e87f3e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
07df716 to
13671a6
Compare
|
@codex review Please review canonical exact W66 head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 13671a6b28
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
fb329d6 to
6e78003
Compare
|
@codex review Please review final canonical exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6e78003cbd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Refs #215 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
fe94290 to
730402f
Compare
|
@codex review Please review final exact W66 head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 730402f79c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| var locator = | ||
| value[4..]; | ||
| if (!IsValidEnvironmentVariableName( | ||
| locator)) |
There was a problem hiding this comment.
Scope credential locators before resolving them
When a principal creates or updates a destination, a reference such as env:KAFDECK_DEPLOYMENT_TOKEN passes because this validation checks only environment-variable syntax; fully qualified paths to unrelated server secrets are likewise accepted. Since ResolveAsync receives only that unrestricted reference and a cancellation token, a caller with notification-profile authority can bind a process-wide secret it is not otherwise authorized to read to a destination it controls and have the adapter transmit or use the resolved value. Use opaque pre-provisioned credential IDs, or enforce a notification-specific locator allowlist and authorization at the resolution boundary.
Useful? React with 👍 / 👎.
| rfc6145 || | ||
| nat64WellKnown || | ||
| nat64LocalUse || |
There was a problem hiding this comment.
Validate configured NAT64 prefixes before admitting DNS answers
On deployments using an RFC 6052 network-specific NAT64 prefix, an attacker-controlled hostname can resolve to that prefix with an embedded private or metadata IPv4 address, and this check admits it because it recognizes only the well-known and local-use NAT64 prefixes; the translator can then reach the prohibited IPv4 target. Fresh evidence in this head is that the newly added transition checks explicitly return only nat64WellKnown and nat64LocalUse, leaving network-specific /32, /40, /48, /56, /64, and /96 prefixes uncovered. Make the address policy aware of configured translation prefixes and validate the extracted IPv4 address before returning the pinned endpoint.
Useful? React with 👍 / 👎.
Authority
W66 #215 is ACTIVE after W62 shared telemetry/event contracts stabilized.
Slice 1 — contract foundation
Safety
Exact head:
730402f79cba52ed666364967c5550523d1e9142.Canonical remediation
4beeab13ab9d251024d95aa28bcf4c6b8f3e9f8a;13671a6b288a309422dafc1460406232b1a0aa30;Final canonical gate
c1e6f1f53ed9c4677b131fa1352a404f7ba6e731;6e78003cbd996f6f7f3a476089be15580d5c657a;DNS/credential execution boundary closeout
730402f79cba52ed666364967c5550523d1e9142;