You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 70fd025
Browse filesBrowse the repository at this point in the historyBrowse files
feat: inject a confined document loader into flatten and schema analysis (#220)
Flattening and schema analysis resolve remote and relative $ref through the spec
package loader, which by default is unsandboxed. A caller processing an untrusted
specification had no way to confine that loading, exposing arbitrary file read
and SSRF (the same class of issue addressed in go-openapi/spec).
Add an injectable, option-aware loader to the two paths that actually load
documents:
- FlattenOpts.PathLoaderWithOptions, forwarded through ExpandOpts. This covers
the whole flatten feature, since ExpandSpec, ResolveRefWithBase and
DeepestRef all go through ExpandOpts.
- SchemaOpts.PathLoaderWithOptions, threaded through AnalyzedSchema and the
recursive Schema() calls; inferFromRef now uses spec.ExpandSchemaWithOptions
(new in spec v0.22.8) instead of the default-settings ExpandSchema. Flatten's
Schema() call sites propagate the loader too.
Set either to a confined loader (e.g. built with loading.WithRoot /
loading.WithHTTPClient, or a restricted loader from go-openapi/loads) to safely
process untrusted specs. Left nil, behavior is unchanged.
The New() analyzer and the diff package were audited and do not load external
documents (in-memory cataloguing and definition-map lookups only), so they need
no loader.
Bumps spec to v0.22.8 (for ExpandSchemaWithOptions) and aligns swag to v0.27.3;
the testintegration module moves to spec v0.22.8 and loads v0.24.1.
Signed-off-by: Frederic BIDON <fredbi@yahoo.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
0 commit comments