fix(browser): harden browser tool safety boundaries

Add policy gates and output redaction for browser/CDP surfaces, strengthen session ownership tracking, and block credential-like query parameters before third-party browser/web backends receive URLs.

Inspired by the agbrowse review: keep local browser magic-link flows possible while preventing cloud reader/browser escalation from receiving opaque token, code, signature, or key query parameters.
This commit is contained in:
yongjin
2026-06-20 22:20:13 +09:00
committed by Teknium
parent 7eb9716ad7
commit a0beb52a50
10 changed files with 522 additions and 34 deletions
+12 -1
View File
@@ -97,7 +97,7 @@ from tools.tool_backend_helpers import ( # noqa: F401
nous_tool_gateway_unavailable_message,
prefers_gateway,
)
from tools.url_safety import async_is_safe_url, normalize_url_for_request
from tools.url_safety import async_is_safe_url, normalize_url_for_request, sensitive_query_param_name
import sys
logger = logging.getLogger(__name__)
@@ -659,6 +659,17 @@ async def web_extract_tool(
"error": "Blocked: URL contains what appears to be an API key or token. "
"Secrets must not be sent in URLs.",
})
sensitive_query_key = sensitive_query_param_name(normalized_url)
if sensitive_query_key:
return json.dumps({
"success": False,
"error": (
"Blocked: URL contains a credential-like query parameter "
f"({sensitive_query_key}). Web extract backends are third-party "
"readers; remove the sensitive query parameter or use a local "
"browser session when this access is explicitly required."
),
})
normalized_urls.append(normalized_url)
debug_call_data = {