Repository navigation
Fix/magic ai extras ssrf media active content - #691
Merged
navneetkumar-pim-webkul merged 8 commits intoSep 9, 2026
Merged
Conversation
testConnection validated api_url with SafeWebhookUrl, then merged the unvalidated extras JSON over the provider overrides, so extras.url replaced the checked endpoint and reached internal hosts. Exception messages are returned verbatim, making it a non-blind SSRF. Route the merge through ProviderOverrides, which strips the keys the platform record owns. Filtering at merge time also neutralises rows persisted before this guard existed, since extras had no validation rule on either FormRequest. Claude-Session: https://claude.ai/code/session_01Es54dGoiX1pP64XqxvJmXw
…ing headers A PDF carrying /OpenAction /JavaScript was stored byte for byte, then linked through Storage::url() on the public disk and rendered in an unsandboxed iframe, so the viewer ran it on the application's own origin with no auth on the URL. Reject those PDFs at upload, and preview through the existing media route, which already gates on the module permission and the path allow list. The content type is mapped from the extension rather than sniffed, and anything not inline-safe falls back to a download. Chrome refuses to load its PDF viewer inside a sandboxed frame under every token combination, so PDFs stay unsandboxed and rely on the upload check plus the response CSP; every other inline type keeps the opaque origin. Claude-Session: https://claude.ai/code/session_01Es54dGoiX1pP64XqxvJmXw
…tion protection Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
Resolves overlap with the MagicAI SSRF (#689) and purifier cache race (#675) fixes that landed on 3.x independently. Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
Parallel workers boot the fixture provider against the shared database before the framework swaps in their per-worker clone, so two workers can both pass the existence check and race into the same CREATE TABLE. The loser now re-checks instead of failing the run. Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
…extras keys The active-content scan read only the first 8MB, so padding a PDF pushed the marker out of the window. Both ends are now scanned under the same cap. Reserved extras keys were stripped case-sensitively while validation matched them lowercased, leaving a persisted 'URL' in the merged provider config, and a JSON list passed validation as though it were an object. Claude-Session: https://claude.ai/code/session_01JfF9ke2aCFppkN9pYbCfKn
navneetkumar-pim-webkul
deleted the
fix/magic-ai-extras-ssrf-media-active-content
branch
September 9, 2026 12:10
There was a problem hiding this comment.
🟡 Changes recommended
The PR title indicates a security fix, but the diff only changes README documentation, so the PR metadata/scope needs to be corrected to match the actual changes.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates the project README to better reflect UnoPim’s positioning (PIM + DAM), document scaling resources, list official extensions, and clarify operational setup details for installation and queue processing.
Changes:
- Refines the introductory product description to include DAM and “product data + digital assets”.
- Expands scalability docs with a whitepaper link and adds an “Extensions” section with official modules/connectors.
- Adds an Elasticsearch optionality note and updates the recommended
queue:workqueue ordering.
File summaries
| File | Description |
|---|---|
| README.md | Documentation updates: product positioning, scaling resources, extensions list, and installation/ops notes (Elasticsearch + queue worker). |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+176
to
+184
| ## 🧩 Extensions | ||
|
|
||
| Free, officially maintained extensions: | ||
|
|
||
| - [**UnoPim DAM**](https://github.com/unopim/unopim-digital-asset-management) — Digital Asset Management: file and directory management, asset upload and preview, metadata tagging, and CSV/XLSX asset assignment. | ||
| - [**Shopify Connector**](https://github.com/unopim/shopify-connector) — sync product data, prices, descriptions, and images with a Shopify store. | ||
| - [**Bagisto Connector**](https://github.com/unopim/bagisto-connector) — sync products, attributes, and media into a [Bagisto](https://bagisto.com/) storefront, with customizable mappings. | ||
|
|
||
| More connectors and modules are listed on the [UnoPim extensions marketplace](https://unopim.com/extensions/). Extensions are ordinary Concord packages — see the [developer documentation](https://devdocs.unopim.com/) to build your own. |
navneetkumar-pim-webkul
added a commit
that referenced
this pull request
Sep 17, 2026
Eight merged pull requests since v3.1.0 carried no changelog entry: the role-escalation and MagicAI SSRF fixes (#689, #690, #691), the export column selection and category keyword matching fixes (#697, #698), the media replacement fix (#709), the Gemini endpoint (#699), the channel deletion fix (#688), the purifier cache race (#675), and the admin UI and configuration work squashed into #700. 3.1.1 is a patch release, so everything is filed under bug fixes and improvements; no feature section. The heading is stamped 3.1.1 to match Core::VERSION, which the branch already carries.
6 tasks
navneetkumar-pim-webkul
added a commit
that referenced
this pull request
Sep 17, 2026
Eight merged pull requests since v3.1.0 carried no changelog entry: the role-escalation and MagicAI SSRF fixes (#689, #690, #691), the export column selection and category keyword matching fixes (#697, #698), the media replacement fix (#709), the Gemini endpoint (#699), the channel deletion fix (#688), the purifier cache race (#675), and the admin UI and configuration work squashed into #700. 3.1.1 is a patch release, so everything is filed under bug fixes and improvements; no feature section. The heading is stamped 3.1.1 to match Core::VERSION, which the branch already carries.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue Reference
Description
How To Test This?
Screenshots
Checklist
vendor/bin/pestpasses locallyvendor/bin/pint --testreports no style issues3.x, the current release line (mastertargets the next major)Documentation