From a494f95bb8fd9328c0d252b2b7e6ca7e0b450881 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Fri, 9 Oct 2026 23:29:43 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[MEDIUM]=20?= =?UTF-8?q?Enhance=20security=20for=20exported=20requests?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Changes directory creation permission for saved HTTP requests from `0o755` to `0o700` in `internal/export/export.go` to prevent unauthorized access by other local users. - Adds `Set-Cookie` to the default list of redacted headers to prevent potential leakage of sensitive server-set session data in exports. Co-authored-by: tejjasdev <213147578+tejjasdev@users.noreply.github.com> --- .jules/sentinel.md | 4 ++++ internal/export/export.go | 5 +++-- 2 files changed, 7 insertions(+), 2 deletions(-) create mode 100644 .jules/sentinel.md diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..3c2e7c7 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2024-05-24 - [Protect Local Exports from Unauthorized Access] +**Vulnerability:** Saved requests were created in a directory with 0755 permissions, making them readable by any user on the system. +**Learning:** For a local developer tool that inspects and exports potentially sensitive HTTP requests (containing auth tokens, cookies, payloads), exporting them with world-readable permissions poses a local privilege escalation/information disclosure risk. +**Prevention:** Use stricter directory creation permissions (0o700) for paths handling sensitive user exports, ensuring only the owner has access. Redact `Set-Cookie` in exports in addition to `Cookie` and `Authorization` headers. diff --git a/internal/export/export.go b/internal/export/export.go index 7b0e25b..95b50a1 100644 --- a/internal/export/export.go +++ b/internal/export/export.go @@ -21,7 +21,7 @@ import ( const Redacted = "REDACTED" // DefaultRedactHeaders lists headers whose values are hidden on export. -var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key"} +var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key", "Set-Cookie"} // skippedInCurl are headers curl sets by itself. var skippedInCurl = map[string]bool{"host": true, "content-length": true, "transfer-encoding": true, "connection": true} @@ -89,7 +89,8 @@ func SaveRequest(dir string, ev events.Event, redact bool) (string, error) { if dir == "" { dir = "." } - if err := os.MkdirAll(dir, 0o755); err != nil { + // Create directory with 0o700 (owner only) to protect saved requests containing sensitive data. + if err := os.MkdirAll(dir, 0o700); err != nil { return "", err } method := cleanName(ev.Request.Method)