Conversation
Replace the literal-host guard with the existing resolved-address transport so mapped metadata addresses cannot bypass protection. Exercise constructor wiring and retain the guard in local TLS tests. Refs LeanerCloud/cloud-commitments-go#25
|
Warning Review limit reached
This review includes 2 billable files and costs up to $0.50.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 13 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Your 81 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
Comment |
|
Exact-head CI completed successfully at b97a8d0: Build & Test run 37240109834 and pre-commit run 37240109843. The independent Astra verdict and native evidence in the PR body cover this same head. CodeRabbit supplied only a review-limit notice, not a substantive review; no billing or review bypass was used. This PR remains open under the recorded real-scenario acceptance hold; green CI is not live Azure/Private Link proof. |
Summary
Use the existing shared resolved-address metadata guard for Azure Key Vault instead of the resolver's literal-host map. This closes the IPv4-mapped metadata-address bypass without changing dependencies or banning private endpoints.
Keep the production transport in the local TLS fixture, and cover constructor-to-GetSecret rejection plus the real SDK request path, authorization header, and returned secret.
Refs LeanerCloud/cloud-commitments-go#25
Exact-head verification
Head:
b97a8d0068878c4ab581d6125e1326588a1c095e.Limits and merge hold
Positive SDK evidence uses synthetic credentials and a local TLS endpoint, not live Azure authentication or a deployed Private Link endpoint. Existing cloud-URL error-path tests run under kernel network denial. The local git-secrets configuration has no patterns, so its Passed status does not establish AWS credential-pattern coverage.
Exact-head CI and project-required real-scenario acceptance remain merge gates. No merge approval is claimed. This does not resolve the broader public-only policy work in LeanerCloud/cloud-commitments-go#20 or #152; #25 remains open for its remaining scope. Labels mirror #25's existing historical classification.