openclaw/extensions/browser
pgondhi987 462b4020bc
fix(browser): block SSRF redirect bypass via real-time route interception (#58771)
Install a Playwright route handler before `page.goto()` so navigations
to private/internal IPs are intercepted and aborted mid-redirect instead
of being checked post-hoc after the request already reached the internal
host. Blocked targets are permanently marked and rejected for subsequent
tool calls.

Thanks @pgondhi987
2026-04-02 09:07:57 -07:00
..
src fix(browser): block SSRF redirect bypass via real-time route interception (#58771) 2026-04-02 09:07:57 -07:00
browser-runtime-api.ts refactor: route plugin sdk through extension barrels 2026-03-27 13:46:16 +00:00
index.test.ts test: drop browser plugin registration smoke 2026-04-01 03:03:27 +01:00
index.ts refactor: add browser plugin runtime package 2026-03-26 22:20:39 +00:00
openclaw.plugin.json refactor: add browser plugin runtime package 2026-03-26 22:20:39 +00:00
package.json build: prepare 2026.4.1-beta.1 release 2026-04-01 15:09:19 +01:00
runtime-api.ts refactor: route plugin sdk facades through extension barrels 2026-03-27 20:47:36 +00:00
test-support.ts refactor: move plugin-owned test support into plugins 2026-03-30 08:03:04 +09:00