Prevent loading files from repos with incorrect names #426
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This change adds a safeguard against accidentally loading files from non-eligible repositories.
Motivation and Context
Framna Docs builds upon loading files from repositories with a specific naming convention ("-openapi" by default). Prior to this change, the GitHub client used would allow loading files from all the repos the user has access to, including ones that do not have the correct name.
Loading files from non-eligible repositories is not a problem per-se, but it is an unexpected behaviour as we are specifically loading data from repositories only with the correct suffix.
It could become an issue if someone gains access to a user's session, as this would allow the exploiter to access files in all repositories that the user has access to. Specifically via the endpoint
/api/blob/[owner]/[repository]/[...path]
which is otherwise only used for loading images. Example:/api/blob/my-org/secret-project/README.md
.Types of changes