Commit Graph
7 Commits
Author SHA1 Message Date
AEmotionStudio 852840dcae refactor(core): restructure project into shared/ and nodes/ modules 2026-01-19 22:02:47 -08:00
google-labs-jules[bot] 1c9ab10e16 security: fix token leakage in API error handling
- Sanitize `DiscordWebhookClient` exception messages to redact webhook tokens.
- Sanitize GitHub API response text in error messages to prevent token leakage.
- Update `tests/test_utils.py` with mocks and new security test cases.
- Record security learning in `.jules/sentinel.md`.

This addresses potential credential exposure in logs and error messages.
2026-01-18 01:36:51 +00:00
google-labs-jules[bot] cd2052757a Enforce HTTPS for Discord webhooks
This change updates the `validate_webhook_url` function to strictly enforce the use of `https://` for Discord webhook URLs. This prevents the accidental transmission of sensitive webhook tokens over unencrypted HTTP connections.

Security Impact:
- Prevents potential Man-in-the-Middle (MitM) attacks from capturing webhook tokens if a user inadvertently copies an `http://` URL (e.g. from a proxy or non-standard source).
- Aligns with Discord's API security best practices.

Changes:
- Updated `WEBHOOK_URL_PATTERNS` regex to require `https`.
- Updated `validate_webhook_url` logic to check for `https://` prefix.
- Added unit test `test_http_url_rejected` to verify the fix.
2026-01-17 01:14:33 +00:00
AEmotionStudio b05b89148e feat: implement comprehensive test suite and enhance security validation 2026-01-14 22:52:38 -08:00
AEmotionStudio 90ad202495 🛡️ Fix SSRF vulnerability in Discord webhook client
- Removed lenient URL validation fallback that allowed bypass attacks
- Added URL validation to send_to_discord_with_retry() before any HTTP request
- Added SSRF regression tests
Resolves: PR #7
2026-01-14 20:04:04 -08:00
AEmotionStudio 6c282d3f1b refactor: Rename utils to discordsend_utils 2026-01-14 16:33:32 -08:00
AEmotionStudio 29a48ae943 Implement structured logging and add tests
- Add `utils/logging_config.py` for logger setup.
- Replace print statements with logging in `utils/discord_api.py`.
- Add `tests/test_utils.py` unit tests.
2026-01-10 18:10:35 -08:00