4 months ago
44527eeSecurity and safety hardening across extraction, path handling, desktop uploads, and mobile-device permissions.
- Add safe in-process ZIP extraction (src/utils/safeZip.ts) and switch archive extractors to use it (artifactRuntime & codexPrimaryRuntime) to avoid shelling out and to enforce per-member containment checks.
- Pin several third-party GitHub Actions to immutable commit SHAs to avoid executing retagged/compromised actions (.github workflows/actions).
- Desktop: implement an authorizeUploadSource flow (IPC + preload changes + API/schema updates) so only paths selected via the renderer file picker can be copied into workspace uploads; enforce a cap on remembered sources and add tests to verify unauthorized sources are rejected (apps/desktop electron & src/lib changes, tests updated/added).
- Add a new `conversations` trusted-device permission and wire it throughout mobile relay, server H3 transport, and desktop UIs; require it for thread/conversation reads and adjust defaults/grandfathering for pre-existing devices.
- Add repo-pinned SHA-256 verification for managed Codex app-server assets before extraction/installation to fail-closed on mismatches (providers/codexAppServerResolver.ts).
- Strengthen session backup handling by validating snapshot paths are contained and resolving snapshot paths safely before filesystem operations (sessionBackup & metadata updates).
- Centralize protected metadata names (".git", ".cowork") and add pathCrossesProtectedMetadata helper; use it in sandbox policy and permission checks so protected metadata remains read-only even under writable roots (src/utils/paths.ts, platform sandbox, permissions util).
- Misc: update tests and add new tests for safe zip handling, session backup path traversal, artifact/codex zip handling, and workflow action pinning.
These changes are aimed at preventing path traversal, accidental/attacker-driven local file reads, unsafe archive extraction, and unauthorized mobile-device access to conversation history.Parentc27db6f