tju-yxq opened a new pull request, #5166:
URL: https://github.com/apache/rocketmq-dashboard/pull/5166

   ### Which Issue(s) This PR Fixes
   
   - Fixes #5165
   
   ### Brief Description
   
   `UrlHostGuard.check` now rejects URLs that embed credentials as user-info 
(`http://user:password@host`) with a message pointing at the dedicated 
credential fields, before any host resolution. The single choke point covers 
data source save/update (credentials belong in the `auth` field), the 
general-settings LLM base URL, and webhook sends. 
`LlmConfigService.isValidApiBase`, which parses its own URI and only consulted 
`isAllowedHost`, rejects user-info the same way via a new 
`UrlHostGuard.hasUserInfo` helper. Clean URLs — including private site-local 
hosts and loopback for local LLM gateways — are unaffected.
   
   ### How Did You Test This Change?
   
   Run on the branch (`af3b16fe`, based on `master` @ `0228dad5`):
   
   ```
   cd server && mvn -B -ntp 
'-Dtest=UrlHostGuardTest,UrlHostGuardMulticastTest,SettingsServiceTest,LlmConfigServiceTest'
 test
   UrlHostGuardMulticastTest: 1, UrlHostGuardTest: 8, LlmConfigServiceTest: 31, 
SettingsServiceTest: 44
   Tests run: 84, Failures: 0, Errors: 0, Skipped: 0 — BUILD SUCCESS
   ```
   
   New coverage: `check` rejects `http://prometheus:[email protected]/metrics` and 
`http://[email protected]/metrics` (user-info without a password) while still 
accepting the same URL without user-info; `createDataSource` rejects a userinfo 
URL with 400 and never reaches the repository; `saveConfig` rejects an LLM base 
URL with embedded credentials as `llm.config.invalid_api_base`. The user-info 
check runs before host resolution, so the new tests need no DNS. The 
pre-existing SSRF suites (loopback, metadata, unique-local IPv6, multicast) all 
pass unchanged. No frontend change: the backend 400 message is shown by the 
existing form error handling, and no new UI text was added.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [x] New UI text has both Chinese and English entries under `web/src/i18n/` 
(no new UI text in this change)
   - [x] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to