fix: various security fixes (#38406)

Addresses a batch of privately reported security issues, grouped by
area:

- **SSRF** - migration PR-patch/asset fetches, OAuth2 avatar & OpenID
discovery, pull-mirror URL re-validation, and the outbound proxy path.
- **Access-token scope** - prevent scope escalation on token creation;
keep public-only tokens confined (feeds, packages, Actions listings,
star/watch lists, limited/private owners).
- **Access control / disclosure** - go-get default-branch leak, webhook
authorization-header leak, watch clearing on private transitions,
label/attachment scoping.
- **Denial of service** - input bounds for npm dist-tags, Debian control
files, Arch file lists, and SSH keys.

### 📌 Attention for site admins

Not breaking - existing configs keep working - but two changes are worth
a look:

- **New SSRF protection** Outbound requests (migrations, OAuth2 avatars,
OpenID discovery, pull mirrors, proxy path) are now validated against
the allow/block host lists. If your instance legitimately reaches
internal hosts, you may need to add them to
`[security].ALLOWED_HOST_LIST` (and the relevant `ALLOW_LOCALNETWORKS`
settings).
- **Deprecation** `[webhook].ALLOWED_HOST_LIST` is deprecated and will
be removed in a future release. Use `[security].ALLOWED_HOST_LIST`
instead; the old key still works for now.

---------

Co-authored-by: TheFox0x7 <thefox0x7@gmail.com>
Co-authored-by: techknowlogick <techknowlogick@gitea.io>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Zettat123 <zettat123@gmail.com>
This commit is contained in:
bircni
2026-07-12 19:14:09 +02:00
committed by GitHub
parent d2bd1589fe
commit f69e15afe7
93 changed files with 1715 additions and 138 deletions
+42
View File
@@ -372,3 +372,45 @@ func testAPIActionsListRepoWorkflows(t *testing.T) {
assert.NotNil(t, run.TriggerActor, "trigger_actor should be populated")
}
}
// TestAPIOrgActionsRunsAccessControl ensures the org-level Actions run/job listing does not
// leak runs/jobs from repos the caller cannot access.
func TestAPIOrgActionsRunsAccessControl(t *testing.T) {
defer tests.PrepareTestEnv(t)()
// org3 has action run 802 (and its jobs) in the private repo5; user28 is an org3 member
// (teams 12/13) with no access to repo5.
token := getUserToken(t, "user28", auth_model.AccessTokenScopeReadOrganization)
req := NewRequest(t, "GET", "/api/v1/orgs/org3/actions/runs").AddTokenAuth(token)
resp := MakeRequest(t, req, http.StatusOK)
runs := DecodeJSON(t, resp, &api.ActionWorkflowRunsResponse{})
for _, r := range runs.Entries {
assert.NotEqual(t, int64(802), r.ID, "must not leak a run from an inaccessible repo")
}
req = NewRequest(t, "GET", "/api/v1/orgs/org3/actions/jobs").AddTokenAuth(token)
resp = MakeRequest(t, req, http.StatusOK)
jobs := DecodeJSON(t, resp, &api.ActionWorkflowJobsResponse{})
for _, j := range jobs.Entries {
assert.NotEqual(t, int64(802), j.RunID, "must not leak a job from an inaccessible repo run")
}
// user1 is a site admin: it normally bypasses the per-repo access filter, but a public-only token
// must stay confined to public repos, so the run/job in the private repo5 must not be listed.
adminPublicOnly := getUserToken(t, "user1", auth_model.AccessTokenScopeReadOrganization, auth_model.AccessTokenScopePublicOnly)
req = NewRequest(t, "GET", "/api/v1/orgs/org3/actions/runs").AddTokenAuth(adminPublicOnly)
resp = MakeRequest(t, req, http.StatusOK)
adminRuns := DecodeJSON(t, resp, &api.ActionWorkflowRunsResponse{})
for _, r := range adminRuns.Entries {
assert.NotEqual(t, int64(802), r.ID, "a public-only admin token must not list a private repo's run")
}
req = NewRequest(t, "GET", "/api/v1/orgs/org3/actions/jobs").AddTokenAuth(adminPublicOnly)
resp = MakeRequest(t, req, http.StatusOK)
adminJobs := DecodeJSON(t, resp, &api.ActionWorkflowJobsResponse{})
for _, j := range adminJobs.Entries {
assert.NotEqual(t, int64(802), j.RunID, "a public-only admin token must not list a private repo's job")
}
}