openclaw/extensions/browser/src
pgondhi987 462b4020bc
fix(browser): block SSRF redirect bypass via real-time route interception (#58771)
Install a Playwright route handler before `page.goto()` so navigations
to private/internal IPs are intercepted and aborted mid-redirect instead
of being checked post-hoc after the request already reached the internal
host. Blocked targets are permanently marked and rejected for subsequent
tool calls.

Thanks @pgondhi987
2026-04-02 09:07:57 -07:00
..
browser fix(browser): block SSRF redirect bypass via real-time route interception (#58771) 2026-04-02 09:07:57 -07:00
cli refactor(plugin-sdk): untangle extension test seams 2026-03-29 23:43:53 +01:00
config fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
gateway fix: stabilize extensions surface test gate 2026-03-30 07:47:58 +09:00
infra fix(ci): route browser tmp path through public temp-path seam 2026-03-27 23:24:57 +00:00
logging fix(ci): narrow browser logger and schema seams 2026-03-27 23:29:59 +00:00
media fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
node-host refactor: move browser tests into plugin 2026-03-26 23:26:37 +00:00
process fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
security fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
test-utils fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
utils fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00
browser-runtime.ts refactor: genericize speech provider config surface 2026-03-26 22:48:57 +00:00
browser-tool.actions.ts
browser-tool.schema.ts fix(ci): narrow browser logger and schema seams 2026-03-27 23:29:59 +00:00
browser-tool.test.ts fix: stabilize extensions surface test gate 2026-03-30 07:47:58 +09:00
browser-tool.ts
control-service.ts fix(ci): narrow browser logger and schema seams 2026-03-27 23:29:59 +00:00
core-api.ts refactor: finish browser compat untangle 2026-03-26 22:42:41 +00:00
plugin-enabled.ts
plugin-service.ts refactor: finish browser compat untangle 2026-03-26 22:42:41 +00:00
server.ts fix(ci): narrow browser logger and schema seams 2026-03-27 23:29:59 +00:00
utils.ts fix(browser): narrow browser support facades 2026-03-27 23:20:24 +00:00