mirror of
https://github.com/openclaw/openclaw.git
synced 2026-04-23 13:38:38 +00:00
fix(security): harden tlon Urbit requests against SSRF
This commit is contained in:
@@ -19,6 +19,7 @@ export const TlonAccountSchema = z.object({
|
||||
ship: ShipSchema.optional(),
|
||||
url: z.string().optional(),
|
||||
code: z.string().optional(),
|
||||
allowPrivateNetwork: z.boolean().optional(),
|
||||
groupChannels: z.array(ChannelNestSchema).optional(),
|
||||
dmAllowlist: z.array(ShipSchema).optional(),
|
||||
autoDiscoverChannels: z.boolean().optional(),
|
||||
@@ -32,6 +33,7 @@ export const TlonConfigSchema = z.object({
|
||||
ship: ShipSchema.optional(),
|
||||
url: z.string().optional(),
|
||||
code: z.string().optional(),
|
||||
allowPrivateNetwork: z.boolean().optional(),
|
||||
groupChannels: z.array(ChannelNestSchema).optional(),
|
||||
dmAllowlist: z.array(ShipSchema).optional(),
|
||||
autoDiscoverChannels: z.boolean().optional(),
|
||||
|
||||
Reference in New Issue
Block a user