openclaw/extensions/browser
pgondhi987 462b4020bc
fix(browser): block SSRF redirect bypass via real-time route interception (#58771)
Install a Playwright route handler before `page.goto()` so navigations
to private/internal IPs are intercepted and aborted mid-redirect instead
of being checked post-hoc after the request already reached the internal
host. Blocked targets are permanently marked and rejected for subsequent
tool calls.

Thanks @pgondhi987
2026-04-02 09:07:57 -07:00
..
src fix(browser): block SSRF redirect bypass via real-time route interception (#58771) 2026-04-02 09:07:57 -07:00
browser-runtime-api.ts
index.test.ts test: drop browser plugin registration smoke 2026-04-01 03:03:27 +01:00
index.ts
openclaw.plugin.json
package.json build: prepare 2026.4.1-beta.1 release 2026-04-01 15:09:19 +01:00
runtime-api.ts
test-support.ts