Skip to content

fix: integrate the bounded Console sharing proxy and credit its reporter - #209

Merged
Vonng merged 2 commits into
mainfrom
codex/credit-console-share-reporter
Sep 16, 2026
Merged

Vonng merged 2 commits into
mainfrom
codex/credit-console-share-reporter

Conversation

@Vonng

@Vonng Vonng commented Sep 16, 2026

Copy link
Copy Markdown
Member

Server's embedded Console still selected a revision that allowed the anonymous sharing endpoint to reach non-object paths such as internal public metrics. Select the immutable Console revision from Console #56, which confines requests to object-content GETs at the configured S3 origin and rejects redirects. Normal public, presigned and versioned sharing remains available; no new environment variable is introduced.

Credit Jiri Pejchal (@jiri-pejchal), who reported the issue in Console #52, in the contributor record and both README contributor lists. His website profile and avatar have already been published. Record the security change and selected version in the unreleased changelog.

Validation: make verifiers (Go lint, generated files, module tidiness, credits and compatibility guards), a clean CGO_ENABLED=0 go build -mod=readonly, and real API/Chromium sharing tests in both embedded and standalone deployments all passed. The binary metadata confirms the selected Console pseudo-version and an unmodified Server commit. Console #56 passed its required CI matrix and vulnerability checks before merging into Console main.

This updates source on main. It does not replace already published Server binaries, packages or images, or publish a new Console release.

Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
@Vonng
Vonng merged commit 3c26a8b into main Sep 16, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant