Files
session-history/ohm/0026/SESSION-0026.3-TRANSCRIPT-2026-05-28T13-46--2026-05-28T13-50.md
Ben Stull 9e6756f678 ohm: migrate orphaned subagent transcripts (0019.x, 0026.x) + renumber dup 0046.0 -> 0073
Backfills transcripts that existed only locally in ohm-infra:
- 0019.1/.2/.3 - UX-polish wave subagent transcripts (driver 0019.0 never finalized)
- 0026.1-.9 - security-audit-0026 subagent transcripts (driver abandoned/closed-out by 0068; audit drove published 0030 remediation)
- 0073.0 - PPE/progressive-delivery + engineering-handbook session, originally drafted as a duplicate 0046.0; reassigned next free number (0072 taken by a concurrent session)

sessions.json: add 0019/0073 titles, update 0026 title.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 03:28:59 -07:00

4.6 KiB

SESSION-0026.3 — OHM security audit subsession: webhooks, CAPTCHA, email

Parent: SESSION-0026.0-TRANSCRIPT-2026-05-28T13-46--INPROGRESS.md Subsession: 0026.3 Mode: READ-ONLY security audit. No mutations. Only file written: this transcript. Target: rfc-app @ v0.24.0 (commit 28015ed), /Users/benstull/git/rfc-app Date: 2026-05-28, America/Los_Angeles

Surface

Webhooks (backend/app/webhooks.py), Turnstile/CAPTCHA (backend/app/turnstile.py), email (email.py, email_otc.py, email_invite.py, email_envelope.py + the api_invitations.py / api_notifications.py call/receive sites).

Pre-state

Came in with the three-part brief (webhook HMAC/replay/unknown-repo; Turnstile verify/fail-open/single-use/coverage; email header-injection/redirect/SSRF). No prior knowledge of these modules.

Turn-by-turn arc

  1. Confirmed tag v0.24.0, read webhooks.py + turnstile.py in full.

    • Webhook: HMAC-SHA256 over the raw await request.body() bytes (good), hmac.compare_digest (good), secret required at config-load (config.py refuses to start without GITEA_WEBHOOK_SECRET unless RFC_APP_INSECURE_WEBHOOKS=1). Verification happens BEFORE any json.loads / cache action. Unknown-repo path (#18) only logs — no unsafe action. No replay/dedup (delivery-id/timestamp).
    • Turnstile: success field checked; network/parse failure -> reason="network" (fail-CLOSED only when TURNSTILE_REQUIRED=true; fail-OPEN by default when secret unset). Token never cached -> single-use enforced by Cloudflare.
  2. Read all email modules + envelope builder. Found a 5th sender (api_invitations.py RFC-invite) beyond the 4 named in the brief — also routes through build_envelope.

  3. Located enforcement sites: Turnstile wired ONLY to /auth/otc/request (main.py:255). Checked beta-request (api.py:441, require_user) and propose (api.py:766, require_contributor) — both require an authenticated session, so Turnstile is correctly unneeded there. The unauthenticated abuse hot path (OTC request) is the one that needs it, and it's covered. -> KILLED the "Turnstile missing on beta/propose" candidate.

  4. Header-injection probe. Empirically tested Python 3.13 EmailMessage:

    • m["To"]=, m["Subject"]=, and formataddr((display,addr)) assignment all raise ValueError on embedded CR/LF (default EmailPolicy). Code uses EmailMessage (NOT legacy email.mime), so the classic header-injection vector is closed at the stdlib layer for To/From/Subject/display-name. -> KILLED "CRLF header injection / BCC smuggling" as exploitable. Downgraded to a minor availability note (a malicious display name -> uncaught ValueError -> 500), needs-verification on whether that path is reachable with attacker text.
  5. email-bounce webhook (api_notifications.py:543): unauthenticated when WEBHOOK_EMAIL_BOUNCE_SECRET unset (the documented v1 dev default); flips email_opt_out_all=1 for any matching user email. Constant-time compare when set.

  6. Confirmed unsubscribe tokens: itsdangerous URLSafeSerializer signed with SECRET_KEY, salt "email-unsubscribe", scoped to (user_id, category). No expiry (intentional, revocable by rotating SECRET_KEY). app_url is operator-controlled (no open-redirect via user input). siteverify URL is fixed (no SSRF).

Cut state — findings

  • F1 (LOW/Medium-conf): email-bounce webhook unauthenticated by default (WEBHOOK_EMAIL_BOUNCE_SECRET unset) -> unauth attacker can force global email opt-out for any known address (DoS on a user's mail). Mitigated in prod IF the secret is wired; needs-verification that OHM's overlay sets it.
  • F2 (INFO): no webhook replay protection (no delivery-id/timestamp dedup) on the Gitea receiver. Low impact — handlers are idempotent cache refreshes, no state mutation from payload contents. Acceptable; documented for completeness.
  • F3 (LOW/availability, needs-verification): malicious display-name containing CR/LF reaching build_envelope raises uncaught ValueError -> 500. Not injection.
  • KILLED: CRLF header injection / BCC smuggling (stdlib guard).
  • KILLED: Turnstile missing on beta-request/propose (both auth-gated).
  • KILLED: Turnstile token replay (not cached; Cloudflare enforces single-use).

Driver needs to know

  • Verify OHM overlay sets WEBHOOK_EMAIL_BOUNCE_SECRET (F1) and TURNSTILE_REQUIRED=true (else Turnstile fails OPEN if the secret regresses).
  • These are env/overlay checks for the flotilla side, not rfc-app code bugs.

§19.2 candidates

  • Webhook delivery-id dedup could become a shared flotilla-core concern if more webhook receivers land. Not urgent.