Skip to content

Security: SSRF validation on import_url endpoints#56

Merged
nicdavidson merged 4 commits intodevelopfrom
2026-04-security-scan
Apr 14, 2026
Merged

Security: SSRF validation on import_url endpoints#56
nicdavidson merged 4 commits intodevelopfrom
2026-04-security-scan

Conversation

@nicdavidson
Copy link
Copy Markdown
Contributor

Summary

  • Add SSRF validation to import_url endpoints across Package, Import, and App services
  • Prevents internal network scanning via crafted import URLs

Test plan

  • Verify legitimate import URLs still work
  • Confirm internal/private IP ranges are blocked
  • Test with localhost, 169.254.x.x, 10.x.x.x URLs

oleksandrkits and others added 4 commits January 20, 2026 18:20
Added standard overview describing DreamFactory as a secure, self-hosted
enterprise data access platform for enterprise apps and on-prem LLMs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The password reset link included &admin=1 for system administrators,
disclosing admin status in emails, browser history, and URL logs.
The frontend can determine admin status after reset via session info.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants