Skip to content

Fix critical cloud tenant isolation boundaries#1229

Draft
Bl3f wants to merge 4 commits into
mainfrom
cursor/fix-critical-tenant-isolation-b591
Draft

Fix critical cloud tenant isolation boundaries#1229
Bl3f wants to merge 4 commits into
mainfrom
cursor/fix-critical-tenant-isolation-b591

Conversation

@Bl3f

@Bl3f Bl3f commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

  • return an explicit safe DTO from project.getCurrent
  • block project and organization admin password resets in cloud and hide those actions in cloud UI
  • canonicalize context file paths to reject symlink escapes
  • authenticate FastAPI internal routes, enforce read-only SQL defense-in-depth, and bind direct FastAPI startup to localhost

Validation

  • repository pre-commit checks pass: TypeScript/ESLint, Prettier, migration checks, ty, and Ruff
  • focused backend regression tests: 13 passed
  • focused FastAPI tests: 14 passed, 2 optional BigQuery tests deselected
Open in Web Open in Cursor 

Review in cubic

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview Deployment

URL https://pr-1229-21b1426.preview.getnao.io
Commit 21b1426

⚠️ No LLM API keys configured - you'll see the API key setup flow when trying to chat.


Preview will be automatically removed when this PR is closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants