Commit Graph
3837 Commits
Author SHA1 Message Date
younesbenallalandGitHub 17fb6960d0 Fix blog canonical URLs 2026-06-28 14:33:39 +02:00
younesbenallalandGitHub b647b3e941 Content/june batch 2026-06-28 14:11:10 +02:00
Baptiste ArnaudandGitHub ab729561d4 🐛 Fix file upload advisory (#2544)
- Removed deprecated viewer upload URL V1/V2 routes and handlers.
- Hardened V3 upload paths by validating session-derived path segments.
- Updated API docs and OpenAPI output to advertise only V3
generate-upload-url.
- Added file-input upload URL test coverage and package test wiring.
2026-06-27 16:32:26 +02:00
Baptiste ArnaudandGitHub 9c81300e5a 🐛 Fix Send Email attachment handling (#2543)
- Restrict Send Email attachments to valid Typebot upload URLs.
- Resolve private Typebot upload URLs to short-lived storage URLs before
sending.
- Enable Nodemailer local file access protection for Send Email
messages.
- Fix WhatsApp public media upload keys to avoid a duplicated public
prefix.
- Add regression tests for rejected attachment origins and valid Typebot
uploads.
2026-06-27 16:30:06 +02:00
Baptiste ArnaudandGitHub 03c8dd967f 🐛 Harden email login codes (#2542)
- Add failed-attempt tracking to verification tokens in Prisma schemas
and the PostgreSQL migration.
- Record invalid email login code attempts with an atomic counter and
retire active login tokens after five failures.
- Mark Auth.js email login verification tokens separately from other
verification-token flows.
- Use cryptographically secure random six-digit email login codes.
- Add auth package Vitest coverage, including parallel failed-attempt
handling.
2026-06-27 15:36:28 +02:00
Baptiste ArnaudandGitHub 06575dfcd4 🐛 Fix custom domain deletion ownership check (#2541)
- Added a scoped custom-domain lookup before provider deletion.
- Used the verified stored domain name for provider and database
deletion.
- Added regression tests for denied cross-workspace deletion attempts
and valid deletion.
2026-06-27 14:34:34 +02:00
Baptiste ArnaudandGitHub c7ae1c162e 🐛 Fix misc errors (#2540)
- Return a no-op response for Stripe subscription updates when the
customer is no longer tied to a workspace.
- Validate user profile string fields against database limits before
Prisma updates.
- Return a bad request for imported typebots missing the legacy start
block or group.
- Truncate saved answer content to the MySQL TEXT byte limit before
persisting.
- Cap WhatsApp interactive body text at Meta's 1024-character limit and
add conversion tests.
2026-06-27 11:07:17 +00:00
Baptiste ArnaudandGitHub 54e1fa1a0f 🐛 Fix WhatsApp audio file upload URLs (#2539)
- Fix WhatsApp audio media conversion for file upload inputs so saved
variables receive the uploaded file URL.
- Keep existing audio reply behavior for text input audio clips and
other non-file inputs.
- Add focused WhatsApp conversion tests for file-upload audio and
preserved audio responses.
2026-06-27 05:59:48 +00:00
Baptiste ArnaudandGitHub b86864ca60 🐛 Improve expired data cleanup reliability (#2536)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
Monthly job / clean (push) Has been cancelled
- Reduces expired chat session delete chunks to keep cleanup
transactions smaller.
- Forces old chat session lookups to use the primary database before
deletion.
- Adds structured progress, timing, and error logging to expired data
cleanup steps.
react-v0.10.5 js-v0.10.5
2026-06-24 18:38:42 +02:00
Baptiste ArnaudandGitHub 248f7515d8 🐛 Fix S3 operations without full config (#2533)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
- Added a shared S3 config guard that requires bucket, endpoint, access
key, and secret key.
- Skipped S3 copy, delete, and URL replacement operations when storage
is not fully configured.
- Moved typebot, workspace, and results cleanup callers to rely on
guarded S3 helpers.
- Added tests for incomplete and complete S3 config detection.
2026-06-18 17:30:39 +02:00
Baptiste ArnaudandGitHub 9224f4f770 🐛 Fix embed video overlay in preview (#2532)
## Summary
- Keeps video bubbles above the absolute typing/background layer in the
embedded chat renderer.
- Applies the same stacking approach to direct video URLs and embedded
video iframes.
- Bumps `@typebot.io/js` and `@typebot.io/react` from `0.10.4` to
`0.10.5`.

## Root cause
Chrome could place the full-size absolute `bubble-typing` layer over
video bubbles because the media content shared the same stacking level.
That made the overlay sit above the HTML video element in builder embed
preview.

## Validation
- `bunx nx typecheck @typebot.io/react`
- `bunx nx build @typebot.io/react --configuration=development`
- `bunx nx format-and-lint`
- Commit hook: `nx affected -t
format-and-lint,lint-repo,check-broken-links,test --parallel=4`

Note: I could not visually verify the exact provided local typebot URL
in this workspace because it returns `Typebot not found` locally.
2026-06-18 16:50:13 +02:00
Baptiste ArnaudandGitHub f00ccba8ed 🐛 Fix stored WhatsApp phone lookup fallback (#2531)
- Fallback to the saved WhatsApp credential name when Meta phone lookup
fails for an existing stored credential.
- Keep new Meta token setup validation strict so setup errors still
surface.
2026-06-17 18:57:26 +02:00
Baptiste ArnaudandGitHub 0b053dc0a2 🔧 Prepare v3.17.2 release (#2530)
## Summary

- Bump the root package version to 3.17.2.
- Add the 3.17.2 changelog section covering WhatsApp forwarding
additions, bug fixes, security, content, and internal updates since
v3.17.1.

## Validation

- `git diff --check`
- `bunx nx format-and-lint`
- Pre-commit hook: `nx affected -t
format-and-lint,lint-repo,check-broken-links,test --parallel=4`
latest v3.17.2
2026-06-17 16:08:39 +02:00
Baptiste ArnaudandGitHub 3db24c49bd 👌 Configure WhatsApp webhook forwarding URL (#2529)
- Adds a WhatsApp webhook forwarding URL field directly in the deploy
UI.
- Moves forwarding enablement to an explicit "Forward webhooks" switch
and keeps forwarded events independent from that switch.
- Normalizes legacy URL-only settings through Zod while preserving
explicit disabled configs.
- Restricts forwarding URLs to HTTP(S) and aligns the production update
script with the shared schema.
- Flushes debounced URL inputs on blur and covers legacy, disabled,
empty-event, and invalid-protocol cases in tests.
2026-06-17 15:56:16 +02:00
Baptiste ArnaudandGitHub c5516cd24c 👌 Configure WhatsApp forwarded events (#2528)
- Add WhatsApp settings to enable forwarding and choose all events,
error statuses, or marketing statuses.
- Forward selected Meta webhook payloads while preserving legacy
errorAndMarketingStatusWebhookForwardUrl behavior.
- Add regression coverage for legacy URLs, disabled configs, and
all-events forwarding.
2026-06-17 12:38:31 +02:00
Baptiste ArnaudandGitHub 3b321f4ba1 🐛 Ignore expected WhatsApp webhook errors (#2527)
- Added a viewer ORPC Sentry filter for expected production WhatsApp
webhook validation failures.
- Kept invalid webhook secret, signature, and payload responses flowing
back to callers without reporting them to Sentry.
2026-06-17 12:37:37 +02:00
Baptiste ArnaudandGitHub c82ac4324a 🐛 Fix embedded audio uploads (#2523)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
- Keep CORS headers on upload proxy error responses.
- Surface failed audio/file uploads as Typebot errors instead of leaving
the recorder stuck.
- Prevent recorded-audio Send clicks from submitting the host page form
in embedded bots.
- Prevent duplicate embed uploads while an upload is already in flight.
- Disable recorder abort while recorded audio is being processed or
uploaded.
- Bump @typebot.io/js and @typebot.io/react to 0.10.4.
2026-06-08 15:52:56 +02:00
Baptiste ArnaudandGitHub b252a9c996 🐛 Fix OpenAI chat completions endpoint (#2522)
- Fixed the OpenAI chat completion handler to explicitly use the AI SDK
chat model for custom base URLs.
- Added regression coverage to verify OpenAI-compatible requests target
`/chat/completions` with the expected payload.
2026-06-08 13:13:36 +02:00
Baptiste ArnaudandGitHub 2fd5510641 🐛 Fix OpenAI audio transcription uploads (#2521)
- Normalize `audio/webm` upload filenames to `.webm` instead of `.weba`.
- Send OpenAI transcription requests with an explicit supported audio
filename.
- Log OpenAI transcription failures as block logs instead of bubbling a
500.
- Add focused tests for WebM upload naming and transcription filename
normalization.
2026-06-08 12:22:08 +02:00
Baptiste ArnaudandGitHub 382a13c2fa 📝 Move database recommendation in self-hosting docs (#2516)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
Monthly job / clean (push) Has been cancelled
- Moved the database recommendation under the "Ready to self-host?"
section.
2026-05-28 15:10:02 +00:00
Baptiste ArnaudandGitHub f170033be0 📝 Recommend Neon in self-hosting docs (#2515)
- Add Neon as the recommended production Postgres provider in
self-hosting docs, with a non-affiliate note.
- Link database recommendations to `https://typebot.com/neon`.
- Ignore `.context` files from Biome checks.
2026-05-28 17:02:54 +02:00
younesbenallalandGitHub f420be5166 📝 Add blog partner links (#2506) 2026-05-28 17:01:45 +02:00
younesbenallalandGitHub 8433793edd 📝 Add WhatsApp chatbot blog posts (#2505) 2026-05-28 17:01:03 +02:00
Baptiste ArnaudandGitHub a9eac5045e 🔧 Copy skills during Conductor setup (#2514)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
- Copy .agents/skills from the repository root during Conductor
workspace setup.
- Copy .claude/skills from the repository root during Conductor
workspace setup.
- Ensure both skill directories exist before copying ignored skill
files.
2026-05-27 06:47:25 +00:00
Baptiste ArnaudandGitHub 08cb6ea10f 🐛 Fix missing result columns in CSV export (#2513)
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
- Append missing result headers to saved column orders so newly added
response blocks stay visible.
- Reuse the normalized column order for selected-results CSV export
instead of a local missing-header fallback.
- Add regression coverage for default, saved, and legacy column orders.
2026-05-25 11:33:23 +02:00
Baptiste ArnaudandGitHub b4a7aab16d 🐛 Fix landing page Discord URL (#2512)
- Fix the landing page Discord redirect to use typebot.io.
- Ignore local Typebot agent and Claude skill directories.
2026-05-25 09:22:52 +00:00
Baptiste ArnaudandGitHub f56c3c3f77 🐛 Block IPv6 unspecified SSRF targets (#2511)
- Block IPv6 unspecified addresses in the shared SSRF IP validator.
- Add validator regressions for compressed and expanded IPv6 unspecified
literals.
- Add a safeKy regression that verifies [::] requests are rejected
before reaching a local IPv6 wildcard listener.
2026-05-24 15:46:09 +02:00
Baptiste ArnaudandGitHub 9ef8081a0a 🔧 Prepare v3.17.1 release (#2509)
- Bump root package version to 3.17.1.
- Add the 3.17.1 changelog section for the upload proxy fix and manual
deploy docs update.
v3.17.1
2026-05-22 16:04:07 +02:00
Baptiste ArnaudandGitHub 9d6708bbee 🐛 Fix upload proxy public URL (#2508)
- Prevent signed upload proxy URLs from using internal request origins
in self-hosted reverse-proxy setups.
- Resolve runtime upload proxy URLs from `NEXT_PUBLIC_VIEWER_URL` and
builder upload proxy URLs from `NEXTAUTH_URL`.
- Add regression coverage for internal container origins like
`https://2e862faf612f:3000`.
2026-05-22 15:56:26 +02:00
Baptiste ArnaudandGitHub 5f01ecff64 📝 Update manual deploy docs for Nx (#2507)
- Update the manual self-hosting deploy guide for the current Nx/Bun
workflow.
- Replace stale PM2 commands with repo-root Nx start commands for
builder and viewer.
- Expand the Nginx sample to cover separate builder and viewer domains
and streaming support.
2026-05-22 13:39:21 +00:00
Baptiste ArnaudandGitHub 31c360a342 🔧 Prepare v3.17.0 release
Create Tag / create-tag (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
Bump root package version to 3.17.0 and add the 3.17.0 changelog section for the release workflow.
v3.17.0
2026-05-21 16:45:10 +00:00
Baptiste ArnaudandGitHub a64e82b612 🐛 Fix unsafe upload URL generation (#2502)
- Replace direct browser presigned PUT uploads with signed Typebot
upload proxy URLs.
- Generate or validate upload object keys server-side while preserving
legacy v1/v2/v3 file-input upload contracts.
- Keep builder slot uploads stable for replaceable assets and use
generated names for runtime file uploads.
- Store active file-input MIME types as safe attachment downloads while
keeping safe image uploads inline.
- Update upload clients and docs to support both raw PUT proxy uploads
and form-data uploads.
2026-05-21 18:37:04 +02:00
Baptiste ArnaudandGitHub c0ffd825e2 🐛 Fix Google Sheets OAuth callback authorization (#2501)
- Secure Google Sheets OAuth state with a signed payload, expiry, user
binding, and HttpOnly nonce cookie.
- Enforce workspace and typebot write authorization before generating
consent URLs and before callback side effects.
- Scope Google Sheets credential creation and typebot updates in a
transaction, and clear the OAuth state cookie after callback.
- Add OAuth state verification to the Forge popup flow and centralize
OAuth block definition lookup.
- Add tests for signed Google Sheets OAuth state parsing and redirect
sanitization.
2026-05-21 17:31:47 +02:00
Baptiste ArnaudandGitHub c549cec651 🐛 Fix PartyKit deploy workflow gate (#2500)
- Limit the PartyKit deploy workflow to pushes that change
`packages/partykit`.
- Remove the broken `turbo-ignore` gate and deploy through the Nx
target.
2026-05-21 15:11:51 +00:00
Baptiste ArnaudandGitHub 36a6186101 🐛 Fix WhatsApp preview webhook authorization (#2499)
- Validate that WhatsApp preview webhook test sessions belong to the
authorized typebot before resuming them.
- Require the preview session to still be waiting on the requested
webhook block.
- Share WhatsApp preview phone normalization between preview creation
and test webhook execution.
2026-05-21 17:01:12 +02:00
Baptiste ArnaudandGitHub e296c870bc 🐛 Fix WhatsApp webhook verification (#2498)
- Verify Meta WhatsApp webhooks with optional app secrets while
preserving soft compatibility for existing credentials.
- Add optional 360Dialog webhook secret validation and update flows for
existing WhatsApp credentials.
- Validate Meta WABA and phone number access, then auto-subscribe the
Meta app to the WABA during setup.
- Clear and disable WhatsApp integration when the active credentials are
removed, including published bot state.
- Preserve raw webhook request bodies, document preview app secret
configuration, and add focused webhook verification tests.
- Update related tooling, Biome ignore rules, opensrc guidance, and
small formatting/type-safety cleanup.
2026-05-21 16:45:32 +02:00
Baptiste ArnaudandGitHub 30cbc616e0 🐛 Fix WhatsApp status forwarding SSRF protection (#2497)
- Use the SSRF-protected safeKy client for workspace-configured WhatsApp
status forwarding URLs.
2026-05-21 15:24:37 +02:00
Baptiste ArnaudandGitHub 5861031f72 🔧 Add WhatsApp status forward URL update script (#2496)
- Add a production script to update the WhatsApp status webhook forward
URL on draft and published typebot settings.
- Register the script in `@typebot.io/scripts` and add the settings
project reference needed for typechecking.
- Ignore local `typebot-prod-db` skill folders for agent tooling.
2026-05-21 11:29:55 +02:00
091db9e06f 📝 Add auth failure troubleshooting section to self-hosting docs (#2495)
- Added an "Authentication fails or users are randomly logged out"
section to `apps/docs/self-hosting/troubleshoot.mdx` covering the common
causes (rotated `NEXTAUTH_SECRET` / `ENCRYPTION_SECRET`, builder/viewer
secret mismatch, mismatched `NEXTAUTH_URL`, unreachable or reset
database).
- Pointed users to tail the builder logs to surface the actual NextAuth
/ Prisma error behind the generic "Check server logs" message.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>
2026-05-21 07:46:17 +00:00
b72a37438f 🐛 Fix Pexels video picker infinite loading loop (#2479)
The Pexels picker could repeatedly fetch the same/empty pages when
changing filters such as Square and scrolling to the bottom. This
happened because the intersection observer kept firing while the last
item stayed visible, pagination did not track whether more results were
available, and duplicated videos could be appended.

This patch:
- uses Pexels 1-based pagination
- tracks whether more videos are available from total_results
- prevents concurrent observer fetches
- resets pagination on search/filter changes
- deduplicates videos by id

before:


https://github.com/user-attachments/assets/f5ca5675-b958-41a7-a4b8-fc92a5576a89


after:


https://github.com/user-attachments/assets/590fc103-9dc9-4a85-b95e-3d1d9f9eefb6

---------

Co-authored-by: Baptiste Arnaud <[email protected]>
Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>
2026-05-21 08:23:51 +02:00
fa7cc8c3f2 👌 (openai) Add Ask Model file search controls (#2483)
Add chunk count and score threshold options to Ask Model, pass them to
the OpenAI file_search tool, and constrain Score threshold to the 0-1
range in the builder.

---------

Co-authored-by: ghisson <ghisson@LAPTOP-DQ8OKN2P>
Co-authored-by: ghisson <[email protected]>
2026-05-21 08:02:44 +02:00
Baptiste ArnaudandGitHub 89682dd4ad 🐛 Sanitize CSV exports against formula injection (#2493)
- Added `sanitizeCsvCell` helper that escapes values starting with `=`,
`+`, `-`, `@`, `\t`, or `\r` with a leading apostrophe to prevent
CSV/formula injection (CWE-1236) in spreadsheet apps.
- Applied sanitization to both server-side CSV streams
(`streamAllResultsToCsv`, `streamAllResultsToCsvV2`) for cells and
headers.
- Applied sanitization to client-side exports (`SelectionToolbar`,
`ExportAllResultsDialog`) for cells and header keys.
2026-05-19 18:46:54 +02:00
Baptiste ArnaudandGitHub 6f915c3096 🐛 Prevent cross-typebot webhook resume IDOR (#2494)
- Scope `result` lookup in `handleExecuteWebhook` to the authorized
`typebotId`, closing a cross-tenant IDOR where a caller with read access
to one typebot could resume another typebot's waiting webhook session by
supplying a foreign `resultId`.
2026-05-19 18:45:19 +02:00
Baptiste ArnaudandGitHub fdcc1784c9 🔧 Hash API tokens (#2492)
- Store newly created API tokens as SHA-256 hashes while returning the
raw token once.
- Authenticate bearer tokens against both hashed and legacy plaintext
records, then lazily hash legacy records on successful use.
- Seed Playwright API tokens as hashes.
- Add Conductor setup and run scripts for local workspaces.
2026-05-19 18:17:11 +02:00
Baptiste Arnaud 060033b8cf 📝 Update commit skill and ignore .pi 2026-05-19 16:48:48 +02:00
6f289f647f 🔒️ Upgrade vulnerable deps (ai v5, nodemailer v8, otel sdk-node 0.217) (#2491)
## Summary

Fixes 18 open Dependabot alerts and migrates affected code to the new
major versions:

- `@opentelemetry/sdk-node` → `^0.217.0` (Prometheus exporter DoS,
GHSA-q7rr-3cgh-j5r3)
- `nodemailer` → `^8.0.5` across all manifests + root override
(GHSA-vvjj-xcjg-gr5g, GHSA-c7w3-x93f-qmm8)
- `ai` → `^5.0.52` (GHSA-rwvc-j5jr-mgvh); legacy 3.x dep removed from
`packages/deprecated/legacy` and replaced with a small in-tree
`OpenAIStream` + `StreamingTextResponse` shim
- Provider SDKs aligned to v5 peer: `@ai-sdk/openai`, `anthropic`,
`groq`, `mistral`, `perplexity`, `deepseek`, `togetherai`, `openRouter`,
`dify-ai-provider`

### AI SDK v4 → v5 migration

- `parseTools`: `parameters` renamed to `inputSchema`
- `runChatCompletion` / `runChatCompletionStream`: `maxSteps` replaced
by `stopWhen(stepCountIs(maxSteps))`;
`usage.{prompt,completion,total}Tokens` replaced by
`totalUsage.{input,output,total}Tokens`
- New `toLegacyDataStream` helper that re-emits the v4 data-stream
protocol (`0:text`, `3:error`, `9:tool_call`, …) so existing consumers
in `embeds/js` and the OpenAI `askAssistant` / `askModel` handlers keep
working
- `compatibility: "strict"` removed from `createOpenAI` (option dropped
in v5)
- `formatDataStreamPart` / `processDataStream` imports moved to
`@ai-sdk/ui-utils` (legacy package pinned at 1.2.11)

### E2E test follow-up

Second commit fixes Playwright tests that broke once the env-resolved
URLs / new SDK surface kicked in:
- `fileUpload`: assert exported URL contains `parseS3PublicBaseUrl()`
(not `S3_ENDPOINT`) so it works with `S3_PUBLIC_CUSTOM_DOMAIN`; verify
post-deletion via cache-busted `request.get` instead of a CDN-cached new
tab.
- `ssrf`: assert on the actual "Security validation failed" log emitted
by the pre-flight check; fixture now maps `response.statusCode` into a
`Status` variable so `Status: …` assertions resolve.
- Root `dev` script includes `@typebot.io/partykit` so the webhook
listener e2e test can hit PartyKit on `:1999`.

Also fixes a pre-existing broken anchor link in `whatsapp-ai-agent.mdx`
that blocked the landing-page link checker.

## Test plan

- [ ] `bunx nx test` passes
- [ ] `bunx nx typecheck` passes
- [ ] `bunx nx affected -t
format-and-lint,lint-repo,check-broken-links,test --parallel=4` passes
(pre-commit)
- [ ] `bun run dev` boots builder, viewer, workflows **and** PartyKit
- [ ] Viewer Playwright suite: `fileUpload.spec.ts`, `ssrf.spec.ts`,
`webhookListener.spec.ts` all green
- [ ] Manual smoke: OpenAI `askAssistant` block streams correctly in the
embed (v4 data-stream protocol preserved)
- [ ] Manual smoke: Anthropic / Mistral / Groq blocks still execute
end-to-end
- [ ] Manual smoke: send a test email through a workspace SMTP block
(nodemailer v8)

---------

Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>
2026-05-19 16:30:36 +02:00
younesbenallalandGitHub 77fd228c96 📝 Update blog content (#2489)
Create Tag / create-tag (push) Has been cancelled
Deploy Partykit server / deploy (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
2026-05-15 11:35:29 +02:00
younesbenallalGitHubCopilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
367de01a5d 📝 Added faq dir + cover image to articles (#2485)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-05-15 11:34:37 +02:00
Kleber RochaandGitHub 5b5f82d6c0 🔒️ Add SSRF_ALLOWED_HOSTS env for self-hosted internal APIs (#2474)
## Summary

Self-hosted deployments often have legitimate internal corporate APIs on
RFC1918 ranges (10/8, 172.16/12, 192.168/16) — e.g., a backend chat API
exposed only on the internal cluster network. Since v3.14, the SSRF
mitigation introduced for [CVE-2025-64709 /
GHSA-8gq9-rw7v-3jpr](https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-8gq9-rw7v-3jpr)
blocks every private range unconditionally, which prevents HTTP Request
blocks (and Function blocks via fetch) from reaching those APIs without
exposing them to the public internet.

The advisory itself listed hostname allowlisting as one of the
recommended mitigations (item #5: "Implement an SSRF-safe proxy or apply
hostname allowlists for outgoing requests"), and this PR implements it
as an opt-in env var.

## What changes

- New env var `SSRF_ALLOWED_HOSTS` (comma-separated hostnames) parsed in
`packages/env`
- `validateHttpReqUrl` now accepts an `allowedHosts` parameter
(symmetric with the existing `lookupHost` injection point); the env var
is the default
- When the URL's hostname matches an entry, `validateIPAddress` is
called with `{ allowPrivateRanges: true }`, which **only** skips the
RFC1918 range checks (10/8, 172.16/12, 192.168/16)

## What the allowlist does NOT relax

Every other protection remains active even for allowlisted hosts:

-  Link-local 169.254.0.0/16 — **the actual CVE vector** (AWS/GCP/Azure
metadata)
-  Loopback 127.0.0.0/8 and IPv6 ::1
-  0.0.0.0/8
-  IPv6 link-local fe80::/10 and unique local fc00::/7
-  Cloud metadata hostnames (\`metadata.google.internal\`,
\`metadata.goog\`, \`metadata\`)
-  \`localhost\` in production
-  Decimal/hex/octal IP encoding bypasses
-  IMDS bypass headers (\`X-aws-ec2-metadata-token*\`,
\`Metadata-Flavor\`)

This is the deliberate design: **even if an attacker controls DNS for an
allowlisted hostname and points it to 169.254.169.254, the link-local
check still fires.** The allowlist intentionally narrows what's relaxed
— corp LAN access, not metadata-service access.

## Test plan

- [x] All existing 53 SSRF tests still pass unchanged (default behavior
preserved when env unset)
- [x] New \`describe\` block covering 14 cases:
- RFC1918 hostnames pass when listed (10/8, 172.16/12, 192.168/16,
direct IP literal)
- Link-local **still blocks** for allowlisted host (DNS hijack defense)
  - Loopback **still blocks** for allowlisted host
- Direct \`169.254.169.254\` IP literal **still blocks** even when
listed
  - \`metadata.google.internal\` **still blocks** even when listed
  - Decimal-encoded metadata IP **still blocks** even when listed
- Default behavior preserved when \`allowedHosts\` is undefined or empty
  - Hostname not in allowlist still blocks
  - Case-insensitive matching (URL parser normalizes hostname)
  - No subdomain wildcarding (exact match only)
- [x] \`bun test\` green: 63/63 in \`validateHttpReqUrl.test.ts\`
- [x] \`tsc --noEmit\` green for \`packages/lib\` and \`packages/env\`
- [x] Full \`nx affected\` test suite green (whatsapp, feature-flags,
spaces, rich-text, root, emails, bot-engine, results, builder, lib — all
passed)

## Use case

Currently, self-hosters facing this hit dead-ends: their internal corp
DNS resolves to 10.x, the validator rejects it, and the only escape
valves are (a) expose the API publicly (security regression — adds
attack surface), (b) downgrade to ≤ v3.13.x (re-introduces the
vulnerable code path), or (c) maintain a fork with the validator patched
(fragile, breaks on every upgrade). An opt-in env var resolves this
without weakening the core mitigation.

I'm opening a companion issue (#2475) explaining the use case in more
detail and to gather feedback if a different design is preferred — happy
to iterate.
2026-05-15 11:30:29 +02:00
Baptiste ArnaudandGitHub 67c7c86b1a Revert Google Sheets picker fixes (#2486, #2487) (#2488)
Create Tag / create-tag (push) Has been cancelled
Deploy Partykit server / deploy (push) Has been cancelled
Deploy Workflows (Fly.io) / deploy (push) Has been cancelled
- Revert #2487 (trigger_onepick OAuth param) and #2486 (setAppId +
NEXT_PUBLIC_GOOGLE_SHEETS_APP_ID env var) which broke the Google Sheets
picker in production.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-05-12 17:12:31 +02:00