Repository navigation
Harden File Sync endpoint validation against SSRF - #1738
Merged
Paul Lizer (paullizer) merged 3 commits intoOct 9, 2026
Merged
Paul Lizer (paullizer) merged 3 commits into
Paul Lizer (paullizer) merged 3 commits into
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve application version conflict at 0.261.314 after the base advanced to 0.261.313. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The target branch advanced to 0.261.313, so this change now ships in 0.261.314. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer)
merged commit Oct 9, 2026
1447daa
into
microsoft:paullizer-react-v2-ui
11 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
0.261.312.token_intent. This change does not repair that separate authentication issue.Linked issue
N/A. Related code-scanning alerts: 1090 and 2098. No GitHub issue was created.
Release Notes & Latest Features
Is this visible to end users?
Is this admin-facing (Admin Settings, governance, deployment, config)?
Should this become a Latest Feature card?
Screenshot needed for the card?
Version bump
application/single_app/config.pyVERSIONthird segment bumped, or not needed because this is docs-onlydeployers/version.txtbumped, or not needed becausedeployers/was not changedTesting / validation
python -m pytest functional_tests\test_file_sync_ssrf_validation.py functional_tests\test_file_sync_azure_files_identity.py functional_tests\test_file_sync_azure_blob_storage.py functional_tests\test_file_sync_onedrive_personal.py -q -k 'not test_file_sync_routes_do_not_disclose_exception_details'- 166 passed, 1 deselected.python -m pytest functional_tests\test_action_app_identity_endpoint_hardening.py -q -k 'endpoint_allowlist or file_sync_reuses_the_shared_allowlist'- 3 passed, 7 deselected.python functional_tests\test_docs_app_surface_coverage.py- 7/7 passed;python functional_tests\test_docs_site_quality.py- 6/6 passed.git diff --check- passed.test_file_sync_routes_do_not_disclose_exception_detailsexpects the old[FileSync] Request failed.tag while the unchanged route uses[FILE_SYNC] Request failed.. The same mismatch failed before this change. The CodeQL alerts require fresh GitHub analysis to determine closure.Documentation
Security checklist
@swagger_route(security=get_auth_security())(N/A; no routes added)sanitize_settings_for_user()(N/A; no frontend settings changes)