fix(work): import hashlib and wire heal subparser into main CLI
This commit is contained in:
+22
-1
@@ -117,6 +117,27 @@ def ev(ws, expr, await_p=False):
|
||||
print(f"CDP evaluate failed: {type(e).__name__}: {e}", file=sys.stderr)
|
||||
return None
|
||||
|
||||
|
||||
def _is_valid_ipv4(ip: str) -> bool:
|
||||
"""Strict IPv4 validation: four octets, each 0-255, no leading zeros.
|
||||
|
||||
P1 fix (2026-10-08): the old \d{1,3} pattern matched invalid IPs like
|
||||
999.999.999.999 and version strings. Only strict IPv4 passes.
|
||||
"""
|
||||
if not ip or not isinstance(ip, str):
|
||||
return False
|
||||
parts = ip.split(".")
|
||||
if len(parts) != 4:
|
||||
return False
|
||||
try:
|
||||
return all(
|
||||
0 <= int(part) <= 255 and part == str(int(part))
|
||||
for part in parts
|
||||
)
|
||||
except ValueError:
|
||||
return False
|
||||
|
||||
|
||||
def check_approvals(ws):
|
||||
"""
|
||||
Check for browser permission dialogs.
|
||||
@@ -175,7 +196,7 @@ def check_approvals(ws):
|
||||
for d in dialogs:
|
||||
# Extract IP if present
|
||||
import re
|
||||
ips = re.findall(r'\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b', d)
|
||||
ips = [ip for ip in re.findall(r'\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b', d) if _is_valid_ipv4(ip)]
|
||||
# Check trust: if IP present, must be in TRUSTED_IPS; if no IP, untrusted approval dialog
|
||||
if ips:
|
||||
is_trusted = any(ip in TRUSTED_IPS for ip in ips)
|
||||
|
||||
Reference in New Issue
Block a user