Files
PaperClipAI/server/src/__tests__/workspace-command-authz.test.ts
DottaandPaperclip 9dd6526b47 fix(security): harden privileged server boundaries (#12776)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The server controls secrets, host files, outbound requests, and
workspace commands
> - A red-team review found cases where restricted callers could cross
these trust boundaries
> - These cases could expose credentials or let untrusted input reach
privileged resources
> - This pull request applies least-privilege checks at each affected
server boundary
> - The benefit is safer agent execution without changing the
private-instance bootstrap contract

## Linked Issues or Issue Description

**What happened?**

Several server paths used authorization, redaction, or content-delivery
rules that were too broad. Restricted agent keys could obtain
company-level operational data. Some adapter and instruction paths could
reach server-owned network or file resources without the required owner
approval.

**Expected behavior**

Paperclip must redact credential values, enforce restricted-key scopes,
guard outbound network access, prevent same-origin script execution, and
reserve host-level file and command controls for authorized operators.

**Steps to reproduce**

1. Configure an authenticated development instance at the parent commit.
2. Exercise the affected APIs with a restricted agent key or a
non-instance-admin company user.
3. Observe that the parent commit returns privileged data or accepts a
privileged operation.
4. Repeat on this branch and observe a redacted response, a safe
download, or an HTTP 403 response.

**Paperclip version or commit**

The findings reproduce from commit `39898ab22` and are fixed by this
pull request.

**Deployment mode**

Authenticated self-hosted server and local development modes.

**Installation method**

Built from source with pnpm.

## What Changed

- Redact generic secret `value` and `token` fields recursively in
structured logs.
- Classify exact and separator-suffixed `KEY` environment names as
secrets in company exports.
- Limit restricted self-identity responses and protect company run, log,
and secret catalog APIs.
- Route HTTP adapter requests through DNS-pinned SSRF protection with
exact private-origin allowlisting.
- Download HTML, SVG, and other script-capable assets with `nosniff` and
a sandbox CSP.
- Require instance-admin access for external instruction roots and
exports that read them.
- Block agent-authenticated host command persistence across supported
workspace runtime shapes.
- Apply the central runtime-management decision before workspace command
controls.
- Keep the documented first-user instance-admin claim contract
unchanged.
- Add regression tests and server-owner configuration documentation.

## Verification

- `pnpm -r typecheck` passes.
- The Node 24 remediation suite passes with 365 tests. It skips 25
environment-gated tests.
- `pnpm build` passes under Node 24.
- `git diff --check` passes.
- The full local runner reaches known macOS-only general-server harness
failures before the serialized route lane. The Linux PR matrix is the
authoritative full-suite gate.

## Risks

- Restricted agent keys now receive HTTP 403 responses from company-wide
run, log, and secret catalog endpoints.
- Script-capable assets now download instead of rendering inline.
- External instruction roots now require instance-admin access.
- Private HTTP adapter endpoints now require an exact origin in
`PAPERCLIP_HTTP_ADAPTER_PRIVATE_ENDPOINT_ALLOWLIST`.
- Public HTTP adapter endpoints remain enabled. Redirects and metadata
or link-local targets remain blocked.
- No database migration is required.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, GPT-5. The exact serving snapshot and context-window size
are not exposed. The model used tool-enabled reasoning, repository
access, code execution, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-03 14:15:32 -05:00

71 lines
2.5 KiB
TypeScript

import { describe, expect, it } from "vitest";
import {
collectExecutionWorkspaceCommandPaths,
collectIssueWorkspaceCommandPaths,
collectProjectExecutionWorkspaceCommandPaths,
collectProjectWorkspaceCommandPaths,
} from "../routes/workspace-command-authz.js";
describe("workspace host-command mutation detection", () => {
it.each([
{
name: "project execution policy commands",
actual: () => collectProjectExecutionWorkspaceCommandPaths({
workspaceRuntime: { commands: [{ name: "seed", command: "pnpm seed" }] },
}),
expected: "executionWorkspacePolicy.workspaceRuntime.commands[0].command",
},
{
name: "project execution policy services",
actual: () => collectProjectExecutionWorkspaceCommandPaths({
workspaceRuntime: { services: [{ name: "web", command: "pnpm dev" }] },
}),
expected: "executionWorkspacePolicy.workspaceRuntime.services[0].command",
},
{
name: "project workspace jobs",
actual: () => collectProjectWorkspaceCommandPaths({
runtimeConfig: { workspaceRuntime: { jobs: [{ name: "build", command: "pnpm build" }] } },
}),
expected: "runtimeConfig.workspaceRuntime.jobs[0].command",
},
{
name: "issue execution workspace services",
actual: () => collectIssueWorkspaceCommandPaths({
executionWorkspaceSettings: {
workspaceRuntime: { services: [{ name: "web", command: "pnpm dev" }] },
},
}),
expected: "executionWorkspaceSettings.workspaceRuntime.services[0].command",
},
{
name: "execution workspace config commands",
actual: () => collectExecutionWorkspaceCommandPaths({
config: { workspaceRuntime: { commands: [{ name: "seed", command: "pnpm seed" }] } },
}),
expected: "config.workspaceRuntime.commands[0].command",
},
{
name: "execution workspace metadata jobs",
actual: () => collectExecutionWorkspaceCommandPaths({
metadata: {
config: { workspaceRuntime: { jobs: [{ name: "build", command: "pnpm build" }] } },
},
}),
expected: "metadata.config.workspaceRuntime.jobs[0].command",
},
])("detects $name", ({ actual, expected }) => {
expect(actual()).toContain(expected);
});
it("ignores descriptive runtime entries without a command field", () => {
expect(collectProjectExecutionWorkspaceCommandPaths({
workspaceRuntime: {
commands: [{ name: "seed" }],
services: [{ name: "web", port: 3100 }],
jobs: [null, "build"],
},
})).toEqual([]);
});
});