Skip to content

[SECURITY] Stacked meta-PR: AR SQLi, CRLF headers, open redirect, cookies, CSRF - #24

Closed
thomasklemm wants to merge 2 commits into
mainfrom
cursor/security-meta-pr-6f27
Closed

thomasklemm wants to merge 2 commits into
mainfrom
cursor/security-meta-pr-6f27

Conversation

@thomasklemm

Copy link
Copy Markdown
Owner

Stacked compiler/runtime security meta-PR. Includes #459 (limit/offset/hash order), #461 (CRLF Location / disposition / Tep+CGI drop), and #464 (positional where/having binds). Extra commits on top. Roundhouse only (runtime/ruby, lowerer, Spinel glue). No Campfire/base-app patches.

Closes #23.

Landed

Pinned with tests/emit_and_run.rs overlays plus tests/param_binds.rs / existing Spinel header and cookie tests.

Skipped (own PRs / out of scope)

  • ActionText XSS #457
  • LIKE escaping #327
  • Path-decode #429
  • Tep HTTP parser #465–#468
  • Campfire app bugs, extra html_escape wrap, unverified mention SGID

Residual risk

  • Raw joins(String) fragments and update_all("sql") strings stay trusted developer SQL (Rails-same). Identifier quoting is still regex allowlist, not quote_column_name.
  • HMAC-only session: a client can read CSRF/return_to from the cookie on cleartext HTTP; flags mitigate the cookie jar, not payload confidentiality.
  • Strict targets that never park Current.controller still render an empty token; implicit verify then fail-closes mutating requests. Ruby/Spinel Campfire is the proven pair.
  • Spinel twins of some emit_and_run overlays remain #[ignore] (toolchain).

No /thermos review on this PR.

Open in Web Open in Cursor 

gregmolnar and others added 2 commits October 6, 2026 09:01
…on CRLF

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Fold rubys#459 (limit/offset/hash order as values) plus string order
parsed as col/table.col with ASC/DESC, and validate last_n/first_n
before mutating. Fold rubys#464 positional where/having binds as a
one-pass split so ? and backslashes in values stay data.

Sanitize head/render locations and headers[]= with a shared
HeaderStore (Puma drop). Share one HttpHeaders helper for Tep/CGI.
Escape CR/LF/NUL in URL filename components; re-allowlist disk
disposition at show.

redirect_to refuses an absolute URL whose host is not this request's
Host. Session/flash cookies get SameSite=Lax and Secure on HTTPS;
signed jar options are honored. HMAC-only session store remains a
named residual (no AES-GCM in this runtime).

CSRF: verify_authenticity_token on shared Base, implicit
protect_from_forgery on, empty session token matches nothing.
Closes #23. Overlay/spinel still mint per-session tokens.

Pin with emit_and_run overlays. Skip ActionText XSS, LIKE, path
decode, Tep parser PRs, and Campfire app patches.

Co-authored-by: Thomas Klemm <github@tklemm.eu>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@thomasklemm thomasklemm closed this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add CSRF protection (real token generation + validation)

3 participants