Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

Harden path/zip extraction and device permissions

4 months ago

44527ee
Authored
mweinbach6/7/2026, 3:05:39 PM
Security and safety hardening across extraction, path handling, desktop uploads, and mobile-device permissions.

- Add safe in-process ZIP extraction (src/utils/safeZip.ts) and switch archive extractors to use it (artifactRuntime & codexPrimaryRuntime) to avoid shelling out and to enforce per-member containment checks.
- Pin several third-party GitHub Actions to immutable commit SHAs to avoid executing retagged/compromised actions (.github workflows/actions).
- Desktop: implement an authorizeUploadSource flow (IPC + preload changes + API/schema updates) so only paths selected via the renderer file picker can be copied into workspace uploads; enforce a cap on remembered sources and add tests to verify unauthorized sources are rejected (apps/desktop electron & src/lib changes, tests updated/added).
- Add a new `conversations` trusted-device permission and wire it throughout mobile relay, server H3 transport, and desktop UIs; require it for thread/conversation reads and adjust defaults/grandfathering for pre-existing devices.
- Add repo-pinned SHA-256 verification for managed Codex app-server assets before extraction/installation to fail-closed on mismatches (providers/codexAppServerResolver.ts).
- Strengthen session backup handling by validating snapshot paths are contained and resolving snapshot paths safely before filesystem operations (sessionBackup & metadata updates).
- Centralize protected metadata names (".git", ".cowork") and add pathCrossesProtectedMetadata helper; use it in sandbox policy and permission checks so protected metadata remains read-only even under writable roots (src/utils/paths.ts, platform sandbox, permissions util).
- Misc: update tests and add new tests for safe zip handling, session backup path traversal, artifact/codex zip handling, and workflow action pinning.

These changes are aimed at preventing path traversal, accidental/attacker-driven local file reads, unsafe archive extraction, and unauthorized mobile-device access to conversation history.

Parentc27db6f

42 files changed
  • .github/actions/setup-bun/action.yml+3−1
  • .github/workflows/claude.yml+3−1
  • .github/workflows/cowork-server-release.yml+3−1
  • .github/workflows/desktop-release.yml+3−1
  • .github/workflows/opencode.yml+4−1
  • apps/desktop/electron/ipc/files.ts+45−1
  • apps/desktop/electron/preload.ts+18−2
  • apps/desktop/electron/services/mobileRelayBridge.ts
+1
−0
  • apps/desktop/electron/services/mobileRelayTypes.ts+1−0
  • apps/desktop/electron/services/serverManager.ts+2−0
  • apps/desktop/src/lib/composerAttachments.ts+1−1
  • apps/desktop/src/lib/desktopApi.ts+7−1
  • apps/desktop/src/lib/desktopSchemas.ts+8−0
  • apps/desktop/src/ui/settings/pages/RemoteAccessPage.tsx+1−0
  • apps/desktop/test/ipc-files.test.ts+67−0
  • docs/websocket-protocol.md+22−2
  • src/artifactRuntime/archive.ts+11−35
  • src/codexPrimaryRuntime/archive.ts+11−35
  • src/platform/sandbox/policy.ts+10−9
  • src/providers/codexAppServerResolver.ts+80−0
  • src/server/sessionBackup.ts+2−1
  • src/server/sessionBackup/metadata.ts+18−1
  • src/server/sessionBackup/snapshot.ts+26−3
  • src/server/transport/h3/pairing.ts+12−0
  • src/server/transport/h3/server.ts+86−18
  • src/utils/paths.ts+27−0
  • src/utils/permissions.ts+39−2
  • src/utils/safeZip.ts+337−0
  • test/artifactRuntimeZip.test.ts+87−0
  • test/ci.workflow.test.ts+4−1
  • test/codexPrimaryRuntimeZip.test.ts+133−0
  • test/fixtures/zipBuilder.ts+123−0
  • test/h3.mobile-http-jsonrpc.test.ts+709−1
  • test/h3.mobile-server-pairing.test.ts+5−0
  • test/h3.pairing-store.test.ts+50−1
  • test/permissions.test.ts+51−4
  • test/providers/codex-app-server-resolver.test.ts+73−0
  • test/safeZip.test.ts+145−0
  • test/session-backup-path-traversal.test.ts+163−0
  • test/tools/tools.edit.test.ts+37−0
  • test/tools/tools.write.test.ts+23−0
  • test/workflow-action-pinning.test.ts+86−0