typebot.io/packages
Baptiste Arnaud 892870ff86
🐛 Fix SSRF safe dispatcher DNS lookup handling (#2462)
- Fix `validatingLookup` to handle `{ all: true }` DNS lookup mode that
undici passes, which returns an array of addresses instead of a single
string
- Add localhost bypass in development mode to match existing
`validateHttpReqUrl` behavior
- Without this fix, `fetch()` in Set Variable code blocks silently
failed for external URLs

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-15 12:05:54 +02:00
..
ai 🐛 Fix SSRF vulnerabilities in forge block handlers (#2428) 2026-04-07 12:37:34 +02:00
auth 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
billing 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
blocks 🐛 Fix credential access control and remove vulnerable S3 upload endpoint (#2459) 2026-04-15 10:39:54 +02:00
bot-engine 🐛 Fix SSRF redirect bypass in HTTP Request and Code blocks (#2432) 2026-04-07 16:41:25 +02:00
chat-api 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
chat-session 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
conditions 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
config 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
credentials 🐛 Fix cross-workspace credential theft via preview endpoint (#2430) 2026-04-07 16:21:17 +02:00
deprecated/legacy 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
emails 🐛 Fix space icon picking and optimistic updates 2026-03-26 16:33:46 +01:00
embeds 🐛 Handle GA script load failure to prevent bot from hanging (#2446) 2026-04-13 12:18:57 +02:00
env 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
events 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
forge Add Ask Model action using OpenAI Responses API (#2455) 2026-04-13 14:02:35 +00:00
groups 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
lib 🐛 Fix SSRF safe dispatcher DNS lookup handling (#2462) 2026-04-15 12:05:54 +02:00
logs 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
partykit 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
playwright 👌 Add time filter to results export and fix CSV download on R2 (#2449) 2026-04-13 15:04:27 +02:00
prisma 👌 Introduce Spaces 2026-03-25 18:17:05 +01:00
radar 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
results 🐛 Add missing date-fns dependencies to @typebot.io/results 2026-04-13 15:10:11 +02:00
rich-text 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
runtime-session-store 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
schemas 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
scripts 🔧 Fix cleanArchivedData script performance 2026-04-02 10:06:00 +02:00
services/feature-flags 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
settings 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
shared-core 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
spaces 🔧 Migrate S3 uploads from presigned POST to presigned PUT (#2429) 2026-04-07 15:34:35 +02:00
telemetry 🐛 Fix PostHog tracking by updating cookie domain to typebot.com (#2447) 2026-04-13 12:08:18 +00:00
templates 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
theme 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
typebot 🐛 Fix cross-workspace credential theft via preview endpoint (#2430) 2026-04-07 16:21:17 +02:00
ui 🐛 Fix editables overflow 2026-03-27 12:31:47 +01:00
user 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00
variables 🐛 Fix SSRF bypass via DNS rebinding in HTTP request and script fetch flows (#2461) 2026-04-15 09:28:06 +00:00
whatsapp 🐛 Fix SSRF vulnerabilities in forge block handlers (#2428) 2026-04-07 12:37:34 +02:00
workspaces 🔧 Remove "baseUrl": "." from tsconfigs 2026-03-25 16:40:12 +01:00