Conversation
…hread creation /threads, /follow, /inline-sync, /inline-version and reply-thread creation ran after _allowed() but before core authz, so under the default open policy any sender could reach them. Gate them (and th: buttons) on the same default-deny _actor_authorized check the other button actions use. Signed-off-by: teknium1 <teknium1@users.noreply.github.com>
Contributor
|
Closed by #107 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
With only
INLINE_TOKENconfigured,_dm_policy/_group_policydefault toopen, so_allowed()passes every sender. Core then default-denies the model turn (it trustsenforces_own_access_policyonly underallowlist), but a few adapter-local paths run before core's authz and were reachable by anyone who could message the bot:/threads on|off|auto|reset— persists per-chat settings to disk/follow//unfollow— flips the dialog follow mode via the sidecar/inline-sync— re-uploads the full command + skill catalog to Inline;/inline-version— discloses plugin/Hermes versionsth:thread buttons —_thread_action_allowedfell back to_allowed(), unlike every other button family which uses_actor_authorizedREADME already says
/inline_syncworks "from an authorized chat" and that buttons never become a bypass when intake is open; the code did not enforce that. Found in the Hermes plugin-catalog review of NousResearch/hermes-agent#125406.What
adapter.pyonly:_dispatch_message, computeactor_authorized = self._actor_authorized(chat_type, from_id)once after the intake checks and require it for the three local command handlers and for reply-thread creation. Unauthorized senders' text now simply continues tohandle_message, where core applies its own authz (pairing/ignore/decline as configured)._thread_action_alloweddrops the_allowed()fallback soth:buttons use the same default-deny check as the other action families.Behaviour for authorized users (allowlist,
INLINE_ALLOW_ALL_USERS,GATEWAY_ALLOWED_USERS, wizard-configured setups) is unchanged.Tests: four existing cases in
tests/adapter-python.test.tsthat exercised these paths with the barebase_extranow setallow_fromfor their sender; one new case (assert_local_commands_require_authorized_sender) covers a stranger under the default policy — red onmain, green here. The embedded Python suite passes (adapter python smoke ok);hermes plugins validateonplugin/inline→ ok, install scanner → safe.