Skip to content

test: allowlist dead-entry + FastAPI dependant-contract guards (PER-15249) - #325

Open
dshoen619 wants to merge 4 commits into
mainfrom
david/per-15249-pdpci-route-auth-coverage-regression-guard-block-merge
Open

test: allowlist dead-entry + FastAPI dependant-contract guards (PER-15249)#325
dshoen619 wants to merge 4 commits into
mainfrom
david/per-15249-pdpci-route-auth-coverage-regression-guard-block-merge

Conversation

@dshoen619

Copy link
Copy Markdown
Contributor

Closes the two remaining gaps for PER-15249 (Route auth-coverage regression guard, block-merge).

Context: most of PER-15249 already shipped

The route-auth regression guard the issue asks for landed with PER-15245 (#321) as horizon/tests/test_route_auth_audit.py: it builds the app the production way (MockPermitPDP_configure_api_routes), walks app.routes, fails any APIRoute lacking a recognized gate (enforce_pdp_token, enforce_pdp_control_key, JWTAuthenticator, require_listener_token — nested closures flattened via get_flat_dependant), flags un-gateable mounts, and single-sources the allowlist from horizon.authentication.PUBLIC_ROUTE_PATHS. The pytests CI job that runs it is already a required status check on main (repo ruleset 11170517), so the block-merge requirement is met. The issue's "middleware invisible to route.dependant" concern is moot: OPAL trigger routes are gated in place by _gate_opal_trigger_routes in horizon/pdp.py, not via middleware.

What this PR adds

Two tests, one file, no production-code changes:

  • test_allowlist_has_no_dead_entries — every PUBLIC_ROUTE_PATHS entry must match a mounted route, so the allowlist can't rot into a pre-authorized hole for a future route to fall into. /scalar is the one documented exception (registered in PermitPDP.__init__ after _configure_api_routes, so it's invisible to the audit-built app); the test also fails if that exemption ever goes stale.
  • test_router_level_dependencies_surface_in_flat_dependant — the issue's "codex-required" empirical proof, now a permanent contract test: include_router(dependencies=[...]) deps and nested Depends() both surface via get_flat_dependant on the resolved FastAPI (0.125.0; pin >=0.115.6,<1), exercised through the audit's own _route_auth_gates helper, with diagnostics for a future FastAPI bump. Uses the repo's Annotated[..., Depends(...)] convention to stay B008-clean.

Verification

  • test_route_auth_audit.py: 8/8 passed (was 6)
  • Full horizon/tests/: 120/120 passed (parity with the pytests job)
  • ruff check clean, ruff format --check clean
  • Red-before-green confirmed out-of-band: replaying the audit logic at pre-fix 02f7655 flags exactly POST /policy-updater/trigger, POST /data-updater/trigger, POST /kong — the three routes PER-15244/15245 gated.
  • Dead-entry test has teeth: injecting a bogus allowlist entry makes it fail.

🤖 Generated with Claude Code

…5249)

The route-auth regression guard PER-15249 asks for already shipped with
PER-15245 as horizon/tests/test_route_auth_audit.py (walks app.routes,
fails any ungated APIRoute, flags un-gateable mounts, single-sources the
allowlist from horizon.authentication.PUBLIC_ROUTE_PATHS). The `pytests`
job that runs it is already a required status check on main, so the
block-merge requirement is met.

This closes the two remaining gaps the issue calls out:

- test_allowlist_has_no_dead_entries: every PUBLIC_ROUTE_PATHS entry must
  match a mounted route, so the allowlist cannot rot into a pre-authorised
  hole. /scalar is the one documented exception (registered in
  PermitPDP.__init__ after _configure_api_routes, invisible to the audit
  app); the test also fails if that exemption ever goes stale.
- test_router_level_dependencies_surface_in_flat_dependant: the
  codex-required empirical proof that include_router(dependencies=[...])
  deps and nested Depends() surface in get_flat_dependant on the resolved
  FastAPI (0.125.0; pin >=0.115.6,<1), with diagnostics for a future bump.

Verified: 8/8 in the file, 120/120 in horizon/tests/, ruff check + format
clean. Red-before-green confirmed out-of-band: replaying the audit at
pre-fix 02f7655 flags exactly /policy-updater/trigger, /data-updater/trigger,
and /kong.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@linear-code

linear-code Bot commented Jul 13, 2026

Copy link
Copy Markdown

PER-15249

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown

🔍 Vulnerabilities of permitio/pdp-v2:next

📦 Image Reference permitio/pdp-v2:next
digestsha256:fc12e880ea91ec43584dfc522cbe40eda21000f8ced00de9ae1ccf4d673413f5
vulnerabilitiescritical: 0 high: 3 medium: 3 low: 1 unspecified: 1
platformlinux/amd64
size132 MB
packages248
📦 Base Image python:3.13-alpine3.23
also known as
  • 3.13.14-alpine3.23
  • e0e75f8d10947da66ae425727cad4e480c65f32018367f4006f9eba40c48cd5c
digestsha256:72c39ab9dbf2227aa91ec2246e6492260ee2530c36bdf37b208394b42d757b60
vulnerabilitiescritical: 0 high: 2 medium: 1 low: 0
critical: 0 high: 2 medium: 2 low: 1 starlette 0.50.0 (pypi)

pkg:pypi/starlette@0.50.0

high 7.5: CVE--2026--54283 Allocation of Resources Without Limits or Throttling

Affected range>=0.4.1
<1.3.1
Fixed version1.3.1
CVSS Score7.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score0.397%
EPSS Percentile33rd percentile
Description

Summary

request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.

Details

request.form() dispatches to a different parser depending on the Content-Type. For multipart/form-data the max_files, max_fields, and max_part_size limits are forwarded to the parser, but for application/x-www-form-urlencoded the parser is constructed without them. It has no max_fields or max_part_size parameter to receive them, and it appends every field with no count check and accumulates each field's name and value with no size check. The configured limits are therefore both unreachable and unenforced for url-encoded bodies.

Because the url-encoded parser does its work synchronously between stream reads, the two attack shapes have different effects:

  • Field count drives CPU and event-loop blocking. A body of ~1,000,000 fields (a sub-10MB payload such as f0=v&f1=v&...) blocks the worker's event loop for several seconds while parsing, during which the worker serves no other request.
  • Field size drives memory. A single large field value (e.g. a 50MB value) is buffered in full to build the FormData, forcing memory allocation proportional to the request body.

The equivalent multipart/form-data request is correctly rejected with 400 Too many fields / 400 Field exceeded maximum size.

Impact

This Denial of service (DoS) vulnerability affects all applications built with Starlette (or FastAPI) that call request.form() on application/x-www-form-urlencoded requests. A single request with a very large number of fields blocks the event loop for several seconds, and a single request with a very large field forces unbounded memory allocation; in either case, parallel requests can render the service unusable. A reverse proxy that enforces a request body size limit reduces but does not eliminate the exposure, since a sub-10MB body is already enough to block the event loop.

Mitigation

Upgrade to a patched version, which forwards max_fields and max_part_size to the url-encoded parser and enforces them while parsing, raising before the oversized field or excess fields are accumulated. The defaults match multipart/form-data (max_fields=1000, max_part_size=1MB) and can be customized via request.form(max_fields=..., max_part_size=...).

high 7.5: CVE--2026--48818 Server-Side Request Forgery (SSRF)

Affected range<1.1.0
Fixed version1.1.0
CVSS Score7.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score0.368%
EPSS Percentile30th percentile
Description

Summary

When serving static files on Windows, StaticFiles resolves the requested path with os.path.realpath. If a UNC path (such as \\attacker.com\share) reaches the resolver, realpath causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account's NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.

Details

StaticFiles.lookup_path() joins the requested path onto the served directory and calls os.path.realpath on the result before checking containment with os.path.commonpath. On Windows, a UNC path is absolute, so os.path.join discards the served directory and realpath resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.

This only affects the default configuration (follow_symlink=False), which uses os.path.realpath. The follow_symlink=True branch uses os.path.abspath, which performs no I/O.

Impact

Applications running on Windows that serve files with StaticFiles (directly, or via a framework built on Starlette such as FastAPI) in the default configuration are affected. StaticFiles is typically unauthenticated, so any client can trigger the SMB connection and leak the service account's NTLMv2 hash. A secondary impact is discovering internal hosts reachable over SMB by timing responses for valid versus invalid addresses.

Mitigation

Applications not running on Windows are not affected. On Windows, serving static files through a dedicated web server (such as nginx or IIS) instead of StaticFiles avoids the issue. Blocking outbound SMB (port 445) from the application host prevents the credential disclosure even if a UNC path is resolved.

medium 6.5: CVE--2026--48710 Improper Validation of Unsafe Equivalence in Input

Affected range<=1.0.0
Fixed version1.0.1
CVSS Score6.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score1.839%
EPSS Percentile77th percentile
Description

Summary

In affected versions, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed.

Details

When a client requests http://example.com/foo, it sends:

GET /foo HTTP/1.1
Host: example.com

Affected versions reconstructed the URL by concatenating http://{host}{path} and re-parsing the result. The Host value is only valid as a uri-host [ ":" port ] per RFC 9112 §3.2, where uri-host follows the restricted host grammar of RFC 3986 §3.2.2. When it contains characters outside that grammar - notably /, ?, or # - those characters move the path/query/fragment boundaries during re-parsing, so the parsed request.url.path no longer matches the path the server actually received. For example:

GET /foo HTTP/1.1
Host: example.com/abc?bar=

reconstructs to http://example.com/abc?bar=/foo, whose parsed path is /abc - even though routing used the real path /foo. The router still dispatches to /foo and the endpoint executes, but any middleware or code that reads request.url.path sees /abc, so path-based authorization checks can be bypassed.

Impact

Any application running an affected version that relies on request.url (or request.url.path) for security-sensitive decisions is affected. The most common case is middleware that gates access to certain path prefixes based on request.url.path. Deployments fronted by a proxy or load balancer are mitigated only if that proxy rejects or normalizes the malformed Host header before forwarding and the application does not trust attacker-controlled host headers (e.g. X-Forwarded-Host) elsewhere.

Mitigation

Upgrade to a patched version, which validates the Host header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing request.url and falls back to scope["server"] for malformed values.

medium 5.3: CVE--2026--48817 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Affected range<1.1.0
Fixed version1.1.0
CVSS Score5.3
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score0.213%
EPSS Percentile12th percentile
Description

Summary

When dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs.

When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lowercased name matches an attribute on the endpoint subclass reaches the endpoint, that attribute is invoked as if it were a request handler. An attacker can use this to reach methods that were never meant to be HTTP handlers, such as internal helpers, without the authorization checks applied by the intended public handler.

Details

HTTPEndpoint uses the client-supplied method name to resolve an instance attribute, without validating it against the set of HTTP verbs the endpoint supports. A method such as _DO_DELETE therefore resolves an attribute like _do_delete and invokes it. Non-standard methods are valid RFC 9110 token methods, so an endpoint must not treat the method name as a trusted attribute selector.

Impact

An application is affected when all of the following hold:

  • It defines an HTTPEndpoint subclass and registers it via Route(...) without an explicit methods= argument.
  • The subclass defines additional methods whose names match a non-standard HTTP-method token shape and that accept a single request argument and return a response.

This also affects frameworks built on Starlette, like FastAPI.

Mitigation

Register HTTPEndpoint subclasses with an explicit methods= argument on the Route, listing only the HTTP verbs the endpoint supports. The route then rejects any other method with 405 Method Not Allowed before it reaches the endpoint, so non-standard methods cannot resolve an attribute.

low 3.7: CVE--2026--54282 Improper Input Validation

Affected range<1.3.0
Fixed version1.3.0
CVSS Score3.7
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score0.187%
EPSS Percentile9th percentile
Description

Summary

In affected versions, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @<!-- -->google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host.

Details

When a client requests a path that does not start with /:

GET @<!-- -->google.com HTTP/1.1
Host: localhost

affected versions reconstruct the URL as http://localhost@<!-- -->google.com. Per RFC 3986 §3.2.1, the substring before @ in the authority is userinfo, so re-parsing yields username = "localhost" and hostname = "google.com", with an empty path:

request.url          == "http://localhost@<!-- -->google.com"
request.url.hostname == "google.com"
request.url.path     == ""

The root cause is that the path is concatenated directly after the host without a separating /, and without validating that it begins with one. Only the Host header was validated when constructing request.url; the path was not.

This requires an ASGI server that forwards a request-target lacking a leading / into scope["path"].

Impact

Any application running an affected version that uses request.url, request.url.netloc, or request.url.hostname for a security-sensitive decision (host-based authorization, redirect/callback base, SSRF target, cache key, audit log) may be affected, when no fronting proxy or load balancer rejects the malformed request-target first.

Note that this is less exploitable than GHSA-86qp-5c8j-p5mr: there, the poison is carried in the Host header, so the real path still routes to a valid endpoint while request.url.path lies. Here, the poison must be carried in the path itself, and that path (@<!-- -->google.com) does not match any registered route, so routing returns 404 and no endpoint handler runs. The exposure is limited to code that reads request.url before routing - notably middleware - or in 404/exception handlers.

Mitigation

Upgrade to a patched version, which prevents the request path from crossing into the URL authority. The request above instead yields http://localhost/@<!-- -->google.com with request.url.hostname == "localhost".

critical: 0 high: 1 medium: 0 low: 0 ddtrace 3.19.8 (pypi)

pkg:pypi/ddtrace@3.19.8

high 7.5: CVE--2026--50271 Uncontrolled Resource Consumption

Affected range<4.8.2
Fixed version4.8.2
CVSS Score7.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score0.441%
EPSS Percentile36th percentile
Description

Impact

Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs (or a single very large value). The tracer allocates a hash-map entry for each pair on every request, causing unbounded CPU and memory consumption and enabling a remote Denial of Service against any HTTP service that has the baggage propagation style enabled.
The baggage propagation style is enabled by default in most affected tracers, so any internet-facing service that has been instrumented with an affected tracer version is exposed unless the propagation style has been explicitly narrowed.

Patches

This is resolved in version 4.8.2 and later of the dd-trace-py library

Workarounds

If users cannot upgrade immediately:

  1. Disable baggage extraction by removing baggage from DD_TRACE_PROPAGATION_STYLE (or DD_TRACE_PROPAGATION_STYLE_EXTRACT if set independently).
  2. Cap the maximum HTTP request header size at an upstream proxy or web server (for example, Apache LimitRequestFieldSize, Nginx large_client_header_buffers, Envoy max_request_headers_kb).

Resources

Related upstream advisories:
opentelemetry-go GHSA-mh2q-q3fh-2475
opentelemetry-dotnet GHSA-g94r-2vxg-569j

critical: 0 high: 0 medium: 1 low: 0 busybox 1.37.0-r30 (apk)

pkg:apk/alpine/busybox@1.37.0-r30?os_name=alpine&os_version=3.23

medium : CVE--2025--60876

Affected range<=1.37.0-r30
Fixed versionNot Fixed
EPSS Score0.285%
EPSS Percentile21st percentile
Description
critical: 0 high: 0 medium: 0 low: 0 unspecified: 1golang.org/x/crypto 0.53.0 (golang)

pkg:golang/golang.org/x/crypto@0.53.0

unspecified : GO--2026--5932

Affected range>=0
Fixed versionNot Fixed
Description

The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown

🔍 Vulnerabilities of permitio/pdp-v2:next

📦 Image Reference permitio/pdp-v2:next
digestsha256:fc12e880ea91ec43584dfc522cbe40eda21000f8ced00de9ae1ccf4d673413f5
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size132 MB
packages248
📦 Base Image python:3.13-alpine3.23
also known as
  • 3.13.14-alpine3.23
  • e0e75f8d10947da66ae425727cad4e480c65f32018367f4006f9eba40c48cd5c
digestsha256:72c39ab9dbf2227aa91ec2246e6492260ee2530c36bdf37b208394b42d757b60
vulnerabilitiescritical: 0 high: 2 medium: 1 low: 0

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR strengthens the existing “fail-closed” route-auth audit by adding two contract-style tests that (1) prevent the public-route allowlist from accumulating dead entries and (2) lock in the FastAPI dependency-flattening behavior the audit relies on.

Changes:

  • Add a test to ensure every PUBLIC_ROUTE_PATHS entry corresponds to an actually-mounted route (with a single, checked exemption for /scalar).
  • Add a contract test proving router-level include_router(..., dependencies=[...]) dependencies and nested Depends() dependencies surface via get_flat_dependant.
  • Update imports/constants in the audit test module to support the new tests.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@dshoen619 dshoen619 self-assigned this Jul 14, 2026
Two test-only fixes from the PR review:

- The nested-flattening pin was vacuous: it reused fake_gate as both the
  router-level dependency and wrapper's sub-dependency, so the subset
  assertion passed via the directly-attached copy without ever exercising
  get_flat_dependant's recursion - the exact regression it names. Use a
  distinct inner_gate reachable only through wrapper, so the assertion
  fails if nested flattening ever breaks. (Verified: inner_gate is absent
  from the route's direct dependants and only surfaces after recursion.)

- The dead-entry failure message now names ALLOWLIST_ENTRIES_NOT_IN_AUDIT_APP
  so a maintainer who adds a genuinely-public route registered after
  _configure_api_routes (the documented /scalar pattern) is pointed at the
  real fix instead of the misleading "route renamed" advice.

Also documents the accepted trade-off of the /scalar exemption: an exempted
path is not covered by the dead-entry rot check. Kept test-only by choice;
the exemption-free alternative (MockPermitPDP mirroring production's
post-config registration) is noted for the future.

Verified: 8/8 in the file, 120/120 in horizon/tests/, ruff check + format clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@dshoen619
dshoen619 requested review from omer9564 and zeevmoney July 14, 2026 10:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants