[E30-S01-T01] Hardened fetch service (core) #311

Open
opened 2026-08-27 08:05:17 +00:00 by kpcto · 0 comments
Owner

Parent story: [E30-S01] Hardened fetch service (core) (#116)

Intent

Implement the core-owned hardened fetch service with SSRF protections.

Acceptance criteria

  • Resolve DNS first and reject private, loopback, link-local, multicast and cloud metadata ranges
  • Re-check after every redirect up to a maximum of three and pin the connection to the pre-resolved address
  • Enforce a 10-second timeout and a 5 MB response cap

Explicitly out of scope

  • The provider allowlist is covered by E30-S02
  • oEmbed resolution is covered by E30-S03

Test plan

  • Run the table-driven SSRF suite covering private ranges, metadata addresses, redirects and DNS rebinding

Rollback note

  • Revert to the prior fetch implementation; the API surface is unchanged

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E30-S01] Hardened fetch service (core) (#116) ## Intent Implement the core-owned hardened fetch service with SSRF protections. ## Acceptance criteria - Resolve DNS first and reject private, loopback, link-local, multicast and cloud metadata ranges - Re-check after every redirect up to a maximum of three and pin the connection to the pre-resolved address - Enforce a 10-second timeout and a 5 MB response cap ## Explicitly out of scope - The provider allowlist is covered by E30-S02 - oEmbed resolution is covered by E30-S03 ## Test plan - Run the table-driven SSRF suite covering private ranges, metadata addresses, redirects and DNS rebinding ## Rollback note - Revert to the prior fetch implementation; the API surface is unchanged ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint M milestone 2026-08-27 08:05:17 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 08:05:17 +00:00
Sign in to join this conversation.