The reference notifier can append to any file on the server; teach exact host matching and surface-only imports #1
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-helloworld#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
postulo-helloworldis the plugin people are told to copy, so what it does wrong gets copied too. Found in the 2026-09-15 audit of the plugin repositories.1. The notifier appends to any path a person types
src/postulo_helloworld/notifier.py:77-82:Path(config["path"]).expanduser().open("a").~/.bashrcor~/.ssh/authorized_keys.Fix: write only inside a directory the operator sets (an environment variable, defaulting to a subdirectory of the data volume), refuse paths that escape it, or simply use
logging. Explain why in a comment, since this is the example others copy.2. Host matching by substring
source.py:83:any(host in url for host in HOSTS), sohttps://evil.test/?hello.examplematches.Fix: compare
urlsplit(url).hostnameexactly (or as a suffix match on a dot boundary), with a test.3. It teaches imports past the surface
notifier.py:24andsource.py:25importpostulo.plugins.base. Everything used (FieldSpec,TestResult,JobPostingData,declares,Manifest) is already onpostulo.plugins.api. Switch now, and add the surface AST check to CI.4. CI and version pin
.forgejo/workflows/ci.yml:39,41runsscripts/compile_messages.py, which the repository does not have.__version__is0.1.0against0.3.0inpyproject.toml.Fix: use the
postulo-messagescompile command and version fromimportlib.metadata.