Commit Graph
4 Commits
Author SHA1 Message Date
Alexandre Teixeira 0784cd2fed fix(review): harden scholarly redirects, editor draft limits, and threat model
- Enforce outbound URL policy on all hops via bounded manual redirects in scholarly lookups
- Guard declared Content-Length in EditorDraftRoute before request body parsing
- Keep scholarly lookup timeouts and budgets as internal constants rather than surface env vars
- Narrow TUI threat-model description around demonstrable host shell bridge behavior
- Add behavioral regression tests for redirect security and pre-parsing body size guards
2026-09-23 12:53:06 +01:00
Léo 130b49f75d docs(security): document the tool approval gate and its default
The post-external-context gate is off unless ODYSSEUS_TOOL_APPROVAL_GATE is
set, but THREAT_MODEL.md described only the untrusted-context wrapper. A reader
auditing the prompt-injection posture would reasonably assume the gate was
active.

State the default, what it blocks when enabled, the two deliberate exemptions,
and note in Known Gaps that the compensating control for the missing shell
sandbox is off by default.
2026-09-23 11:09:48 +02:00
RaresKeYandAlexandre Teixeira 0dd70a7556 feat(auth): define Default/Local owner contract (#5795)
* feat(auth): define default local owner contract

* test(auth): harden default local owner matrix

---------

Co-authored-by: Alexandre Teixeira <111787685+alteixeira20@users.noreply.github.com>
2026-08-15 20:27:26 +01:00
Povilas Kirna a9580aae7f docs: add THREAT_MODEL.md (#1111) 2026-06-02 22:40:37 +09:00