Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
## 2024-05-24 - [Protect Local Exports from Unauthorized Access]
**Vulnerability:** Saved requests were created in a directory with 0755 permissions, making them readable by any user on the system.
**Learning:** For a local developer tool that inspects and exports potentially sensitive HTTP requests (containing auth tokens, cookies, payloads), exporting them with world-readable permissions poses a local privilege escalation/information disclosure risk.
**Prevention:** Use stricter directory creation permissions (0o700) for paths handling sensitive user exports, ensuring only the owner has access. Redact `Set-Cookie` in exports in addition to `Cookie` and `Authorization` headers.
5 changes: 3 additions & 2 deletions internal/export/export.go
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ import (
const Redacted = "REDACTED"

// DefaultRedactHeaders lists headers whose values are hidden on export.
var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key"}
var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key", "Set-Cookie"}

// skippedInCurl are headers curl sets by itself.
var skippedInCurl = map[string]bool{"host": true, "content-length": true, "transfer-encoding": true, "connection": true}
Expand Down Expand Up @@ -89,7 +89,8 @@ func SaveRequest(dir string, ev events.Event, redact bool) (string, error) {
if dir == "" {
dir = "."
}
if err := os.MkdirAll(dir, 0o755); err != nil {
// Create directory with 0o700 (owner only) to protect saved requests containing sensitive data.
if err := os.MkdirAll(dir, 0o700); err != nil {
return "", err
}
method := cleanName(ev.Request.Method)
Expand Down
Loading