Skip to content

fix: prevent credential leakage via header injection and redirects - #1097

Merged
ehsavoie merged 1 commit into
mainfrom
9rhm-fix
Aug 26, 2026
Merged

fix: prevent credential leakage via header injection and redirects#1097
ehsavoie merged 1 commit into
mainfrom
9rhm-fix

Conversation

@kabir

@kabir kabir commented Aug 26, 2026

Copy link
Copy Markdown
Collaborator
  • Add safe header allowlist validation to AuthInterceptor
  • Disable automatic HTTP redirects in all HTTP clients
  • Add 14 security regression tests
  • Add security documentation page

Fixes GHSA-9rhm-2h4x-jwmx

- Add safe header allowlist validation to AuthInterceptor
- Disable automatic HTTP redirects in all HTTP clients
- Add 14 security regression tests
- Add security documentation page

Fixes GHSA-9rhm-2h4x-jwmx
@ehsavoie
ehsavoie merged commit 2a36530 into main Aug 26, 2026
21 checks passed
@ehsavoie
ehsavoie deleted the 9rhm-fix branch August 26, 2026 15:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants