Skip to content

Fix/magic ai extras ssrf media active content - #691

Merged
navneetkumar-pim-webkul merged 8 commits into
3.xfrom
fix/magic-ai-extras-ssrf-media-active-content
Sep 9, 2026
Merged

navneetkumar-pim-webkul merged 8 commits into
3.xfrom
fix/magic-ai-extras-ssrf-media-active-content

Conversation

@navneetkumar-pim-webkul

Copy link
Copy Markdown
Collaborator

Issue Reference

Description

How To Test This?

Screenshots

Checklist

  • vendor/bin/pest passes locally
  • vendor/bin/pint --test reports no style issues
  • Tailwind classes are reordered
  • New user-facing strings use translation keys (all 33 locales)
  • Target branch is 3.x, the current release line (master targets the next major)

Documentation

  • My pull request requires an update on the documentation repository.

testConnection validated api_url with SafeWebhookUrl, then merged the
unvalidated extras JSON over the provider overrides, so extras.url replaced
the checked endpoint and reached internal hosts. Exception messages are
returned verbatim, making it a non-blind SSRF.

Route the merge through ProviderOverrides, which strips the keys the platform
record owns. Filtering at merge time also neutralises rows persisted before
this guard existed, since extras had no validation rule on either FormRequest.

Claude-Session: https://claude.ai/code/session_01Es54dGoiX1pP64XqxvJmXw
…ing headers

A PDF carrying /OpenAction /JavaScript was stored byte for byte, then linked
through Storage::url() on the public disk and rendered in an unsandboxed
iframe, so the viewer ran it on the application's own origin with no auth on
the URL.

Reject those PDFs at upload, and preview through the existing media route,
which already gates on the module permission and the path allow list. The
content type is mapped from the extension rather than sniffed, and anything
not inline-safe falls back to a download.

Chrome refuses to load its PDF viewer inside a sandboxed frame under every
token combination, so PDFs stay unsandboxed and rely on the upload check plus
the response CSP; every other inline type keeps the opaque origin.

Claude-Session: https://claude.ai/code/session_01Es54dGoiX1pP64XqxvJmXw
Resolves overlap with the MagicAI SSRF (#689) and purifier cache race (#675)
fixes that landed on 3.x independently.

Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
Parallel workers boot the fixture provider against the shared database before
the framework swaps in their per-worker clone, so two workers can both pass the
existence check and race into the same CREATE TABLE. The loser now re-checks
instead of failing the run.

Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
…extras keys

The active-content scan read only the first 8MB, so padding a PDF pushed the
marker out of the window. Both ends are now scanned under the same cap.

Reserved extras keys were stripped case-sensitively while validation matched
them lowercased, leaving a persisted 'URL' in the merged provider config, and a
JSON list passed validation as though it were an object.

Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
Copilot AI lite review requested due to automatic review settings September 9, 2026 12:09
@navneetkumar-pim-webkul
navneetkumar-pim-webkul merged commit a8be532 into 3.x Sep 9, 2026
23 checks passed
@navneetkumar-pim-webkul
navneetkumar-pim-webkul deleted the fix/magic-ai-extras-ssrf-media-active-content branch September 9, 2026 12:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The PR title indicates a security fix, but the diff only changes README documentation, so the PR metadata/scope needs to be corrected to match the actual changes.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates the project README to better reflect UnoPim’s positioning (PIM + DAM), document scaling resources, list official extensions, and clarify operational setup details for installation and queue processing.

Changes:

  • Refines the introductory product description to include DAM and “product data + digital assets”.
  • Expands scalability docs with a whitepaper link and adds an “Extensions” section with official modules/connectors.
  • Adds an Elasticsearch optionality note and updates the recommended queue:work queue ordering.
File summaries
File Description
README.md Documentation updates: product positioning, scaling resources, extensions list, and installation/ops notes (Elasticsearch + queue worker).
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md
Comment on lines +176 to +184
## 🧩 Extensions

Free, officially maintained extensions:

- [**UnoPim DAM**](https://github.com/unopim/unopim-digital-asset-management) — Digital Asset Management: file and directory management, asset upload and preview, metadata tagging, and CSV/XLSX asset assignment.
- [**Shopify Connector**](https://github.com/unopim/shopify-connector) — sync product data, prices, descriptions, and images with a Shopify store.
- [**Bagisto Connector**](https://github.com/unopim/bagisto-connector) — sync products, attributes, and media into a [Bagisto](https://bagisto.com/) storefront, with customizable mappings.

More connectors and modules are listed on the [UnoPim extensions marketplace](https://unopim.com/extensions/). Extensions are ordinary Concord packages — see the [developer documentation](https://devdocs.unopim.com/) to build your own.
navneetkumar-pim-webkul added a commit that referenced this pull request Sep 17, 2026
Eight merged pull requests since v3.1.0 carried no changelog entry: the
role-escalation and MagicAI SSRF fixes (#689, #690, #691), the export
column selection and category keyword matching fixes (#697, #698), the
media replacement fix (#709), the Gemini endpoint (#699), the channel
deletion fix (#688), the purifier cache race (#675), and the admin UI
and configuration work squashed into #700.

3.1.1 is a patch release, so everything is filed under bug fixes and
improvements; no feature section.

The heading is stamped 3.1.1 to match Core::VERSION, which the branch
already carries.
navneetkumar-pim-webkul added a commit that referenced this pull request Sep 17, 2026
Eight merged pull requests since v3.1.0 carried no changelog entry: the
role-escalation and MagicAI SSRF fixes (#689, #690, #691), the export
column selection and category keyword matching fixes (#697, #698), the
media replacement fix (#709), the Gemini endpoint (#699), the channel
deletion fix (#688), the purifier cache race (#675), and the admin UI
and configuration work squashed into #700.

3.1.1 is a patch release, so everything is filed under bug fixes and
improvements; no feature section.

The heading is stamped 3.1.1 to match Core::VERSION, which the branch
already carries.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants