Skip to content

Harden Anthropic localhost URL scheme validation - #63

Merged
christopherkarani merged 1 commit into
mainfrom
codex/check-frameworks-for-issues-20260518
May 18, 2026
Merged

christopherkarani merged 1 commit into
mainfrom
codex/check-frameworks-for-issues-20260518

Conversation

@christopherkarani

Copy link
Copy Markdown
Owner

Summary

This PR fixes a configuration-validation gap in Anthropic URL security checks and adds a regression test.

Root Cause

AnthropicConfiguration.validateSecureURL(_:) previously allowed any scheme for localhost hosts because localhost bypassed the scheme guard unconditionally:

  • accepted: https://... (intended)
  • accepted: http://localhost... (intended for local dev)
  • accepted: ftp://localhost... and other non-HTTP schemes (unintended)

That behavior weakens configuration safety and can route requests through unsupported or insecure schemes while appearing valid.

Changes

1) Added failing test first (TDD)

  • File: Tests/ConduitTests/Providers/Anthropic/AnthropicProviderTests.swift
  • New test: Localhost non-HTTP schemes are rejected
  • Asserts AnthropicConfiguration(baseURL: ftp://localhost:8080) throws AIError.

2) Hardened URL validation logic

  • File: Sources/Conduit/Providers/Anthropic/AnthropicConfiguration.swift
  • Validation now allows:
    • https for all hosts
    • http only for localhost loopback hosts (localhost, 127.0.0.1, ::1)
  • Non-HTTP schemes on localhost are now rejected.

Why this is correct

  • Preserves documented/expected developer behavior for local HTTP testing.
  • Preserves production security requirement of HTTPS for non-local hosts.
  • Closes unintended acceptance path for unsupported schemes.

Verification

  • swift test (full suite): passed
  • swift build: passed

Risk / Compatibility

  • Low risk; change is narrowly scoped to configuration input validation.
  • Potential behavior change only for previously accepted invalid configs (e.g., ftp://localhost...), which now fail fast with a typed input error.

@christopherkarani
christopherkarani merged commit 4f5cb72 into main May 18, 2026
0 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant