Skip to content

Harden File Sync endpoint validation against SSRF - #1738

Merged
Paul Lizer (paullizer) merged 3 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-file-sync-ssrf
Oct 9, 2026
Merged

Paul Lizer (paullizer) merged 3 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-file-sync-ssrf

Conversation

@paullizer

Copy link
Copy Markdown
Collaborator

Summary

  • Restrict Azure Files URLs to canonical Azure File service hostnames for supported clouds, at configuration time and again before token-credential SDK construction. This prevents arbitrary HTTPS hosts from reaching the client boundary, including for saved sources.
  • Add behavioral SSRF regression tests for Azure Files and the already-guarded OneDrive browse-path flow. Document the supported endpoints and compatibility boundaries; bump the application version to 0.261.312.
  • Azure Files token-auth SDK behavior remains unchanged: the current pinned SDK rejects token credentials without token_intent. This change does not repair that separate authentication issue.

Linked issue

N/A. Related code-scanning alerts: 1090 and 2098. No GitHub issue was created.

Release Notes & Latest Features

  • New Feature
  • Bug Fix
  • UI Enhancement
  • Breaking Change
  • Internal only

Is this visible to end users?

  • Yes
  • No

Is this admin-facing (Admin Settings, governance, deployment, config)?

  • Yes
  • No

Should this become a Latest Feature card?

  • Yes
  • No
  • Already added

Screenshot needed for the card?

  • Yes
  • No
  • Attached

Version bump

  • application/single_app/config.py VERSION third segment bumped, or not needed because this is docs-only
  • deployers/version.txt bumped, or not needed because deployers/ was not changed

Testing / validation

  • python -m pytest functional_tests\test_file_sync_ssrf_validation.py functional_tests\test_file_sync_azure_files_identity.py functional_tests\test_file_sync_azure_blob_storage.py functional_tests\test_file_sync_onedrive_personal.py -q -k 'not test_file_sync_routes_do_not_disclose_exception_details' - 166 passed, 1 deselected.
  • python -m pytest functional_tests\test_action_app_identity_endpoint_hardening.py -q -k 'endpoint_allowlist or file_sync_reuses_the_shared_allowlist' - 3 passed, 7 deselected.
  • python functional_tests\test_docs_app_surface_coverage.py - 7/7 passed; python functional_tests\test_docs_site_quality.py - 6/6 passed.
  • Python compile check and git diff --check - passed.
  • The full provider command had 166 passed and 1 pre-existing failure: test_file_sync_routes_do_not_disclose_exception_details expects the old [FileSync] Request failed. tag while the unchanged route uses [FILE_SYNC] Request failed.. The same mismatch failed before this change. The CodeQL alerts require fresh GitHub analysis to determine closure.

Documentation

  • Release notes updated, or not needed (not updated; release-note update was not confirmed)
  • Feature documentation updated, or not needed
  • Fix documentation updated, or not needed

Security checklist

  • New Flask routes include @swagger_route(security=get_auth_security()) (N/A; no routes added)
  • Settings sent to non-admin frontends use sanitize_settings_for_user() (N/A; no frontend settings changes)
  • Browser JavaScript is served from local SimpleChat static assets only; no CDN-hosted JS (N/A; no browser assets changed)
  • No secrets, keys, connection strings, or local-only artifacts are included

Paul Lizer (paullizer) and others added 3 commits October 9, 2026 09:34
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve application version conflict at 0.261.314 after the base advanced to 0.261.313.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The target branch advanced to 0.261.313, so this change now ships in 0.261.314.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paullizer
Paul Lizer (paullizer) merged commit 1447daa into microsoft:paullizer-react-v2-ui Oct 9, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant